CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

Iranian RATs targeting macOS, 22,000 unpatched Exchange servers, and METR API key breach

Today's briefing covers Iranian cross-platform malware targeting Linux and macOS, exposed Microsoft Exchange servers, social engineering tactics, and AI credit theft.

Threat actors are increasingly focusing on cross-platform reach and repeatable, low-complexity delivery mechanisms. Iranian group Nimbus Manticore is deploying Node.js and JavaScript malware against macOS and Linux targets disguised as hiring tasks, while ClickFix techniques exploit user interaction to bypass scanning defenses entirely.

At the same time, infrastructure vulnerability management remains a primary exposure point. Nearly 22,000 Microsoft Exchange servers remain vulnerable to complete mailbox compromise, demonstrating how basic perimeter hygiene continues to lag behind known threat vectors.

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.

Why it matters
Organizations running unpatched Exchange servers face immediate risk of full email compromise, data exfiltration, and lateral movement across their enterprise network.
What to do
Patch exposed Microsoft Exchange servers immediately to resolve the authentication bypass vulnerability.
  • Microsoft
  • Exchange
  • patch
Read the original

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.

  • macOS
  • Linux
  • phishing
  • malware
Read the original

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Threat actors are heavily favoring simple, repeatable attack methods. Microsoft reports ClickFix social engineering—where users are tricked into running clipboard commands via terminal—accounted for 47% of initial access attacks, while Bitdefender found 84% of high-severity incidents leveraged living-off-the-land…

Why it matters
Attacks increasingly bypass traditional security tools because they rely on user actions and legitimate system binaries rather than custom malware or software exploits.
  • endpoint
Read the original

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

profit METR disclosed two security incidents in 2026. In March, threat actors stole an inference API key and consumed approximately $600,000 in AI credits. In May, attackers systematically probed public infrastructure and attempted to exploit an exposed endpoint.

Why it matters
Exposed API credentials and misconfigured public endpoints can lead to massive financial loss through resource abuse, even if underlying internal data remains intact.
  • API
Read the original

Five Venezuelans plead guilty to ATM jackpotting attacks in US

Five Venezuelan nationals pleaded guilty in the US to executing ATM jackpotting attacks that deployed malware to force cash dispensers to empty physical currency.

  • ATM
  • malware
Read the original

Key takeaways

  • Nimbus Manticore uses trojanized coding tests containing NodeRabbit and PollCat malware to target macOS and Linux platforms.
  • Nearly 22,000 exposed Microsoft Exchange servers remain unpatched against an authentication bypass flaw allowing mailbox compromise.
  • ClickFix social engineering was observed by Microsoft as the most common initial access vector last year, accounting for 47% of notifications.
  • Attackers compromised an API key at AI research non-profit METR, consuming approximately $600,000 in inference credits.
  • NimbusManticore
  • NodeRabbit
  • PollCat
  • RAT
  • SpearPhishing