DAILY BRIEFING
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Today's briefing covers global RMM phishing campaigns, abuse of the Node.js runtime, Plex security patches, infostealer risks, and Windows desktop reset issues.
5 stories2 min read

Security teams must prioritize auditing external software management tools and monitoring process activity from legitimate developer runtimes. Additionally, enterprise software maintainers and system administrators need to address immediate patching requirements for Plex applications and navigate recent stability issues caused by Windows preview updates.
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealer malware logs leak credentials and active session tokens, enabling attackers to bypass multi-factor authentication (MFA). Flare highlighted strategies for security teams to evaluate compromised identities, verify active sessions, and remediate affected accounts before unauthorized access leads to takeover.
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
ANY.RUN research revealed a global phishing campaign active in 46 countries that uses lure documents themed around tax forms, shipping notices, and government agencies. The operation relies on disposable Vercel infrastructure to deliver unauthorized remote monitoring and management (RMM) software.
- Why it matters
- Organizations globally, particularly in the US, face unauthorized RMM software deployments that enable persistent remote access for threat actors.
Plex warns users to patch security vulnerabilities immediately
Plex has issued an urgent advisory requesting users to update their desktop clients and media server installations immediately to patch multiple security vulnerabilities.
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Symantec reported that threat actors are abusing the legitimate, signed Node.js runtime (node.exe) to deliver malicious JavaScript payloads. The activity targeted government, tech, and hospitality sectors using techniques like EtherHiding and registry Run keys for persistence.
- Why it matters
- Attackers bypass signature-based security controls by executing malicious JavaScript scripts inside official, trusted software binaries.
Microsoft says KB5120998 Windows update resets desktop settings
Microsoft confirmed an issue in the KB5120998 August 2026 preview update for Windows where desktop settings are reset or lost after installation.
- Why it matters
- Windows end users and system administrators installing preview updates face configuration loss and unexpected desktop behavior.
Key takeaways
- ANY.RUN linked 601 cases of an RMM phishing campaign across 46 countries, with 45% of targeting directed at the United States.
- Symantec reported threat actors using official, signed Node.js binaries (node.exe) to execute malicious scripts and maintain persistence.
- Plex urged users to immediately update desktop clients and media servers to resolve multiple security vulnerabilities.
- Microsoft confirmed the KB5120998 August 2026 preview update causes desktop settings to reset or be lost on affected Windows devices.