Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 AWS access keys exposed publicly between 2022 and 2026 remain active, according to research that scanned code repositories, Docker images, and CI logs for exposed secrets. Researchers found over 800 keys tied to identifiable companies, including hundreds of root keys and IAM users with full administrator access, meaning a majority could hand an attacker complete control of a victim’s cloud account. Hugging Face was the single largest source of exposure, and most of the leaked credentials were years old and had never been rotated, underscoring how routinely committed secrets go unnoticed.
You don’t want this Sleepwalker backdoor on your Windows machine
A previously undocumented Windows backdoor named Sleepwalker sits passively in memory, disguised as a legitimate ESET component, until a specially crafted network packet wakes it and delivers commands written in its own 23-instruction command language. Because it never initiates outbound connections or opens a listening port, the malware evades typical network monitoring entirely, and researchers say its design points to a well-resourced, targeted operation rather than an opportunistic one. Much about its origin and scope remains unknown, but the analyst behind the discovery has released detection and mitigation tooling for anyone who suspects an infection.
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A patched Zimbra Collaboration flaw that allows unauthenticated remote code execution through crafted SNMP notifications is now being actively exploited, according to Poland’s national CERT. The bug affects installations with the optional SNMP package enabled and lets an attacker run arbitrary operating system commands without credentials; a fix has been available since last month, and the vulnerability has since been added to the US government’s known-exploited list with a remediation deadline. Zimbra servers have repeatedly been a target for state-linked phishing and espionage campaigns, making prompt patching especially important for organizations still running vulnerable versions.
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
An Iran-linked cyberattack knocked a British power generation facility offline for four days in July, a disruption that only became public this week after reporting by a UK newspaper rather than official disclosure. Analysts note the target was a relatively small, distributed energy asset rather than a major plant, but they warn the incident demonstrates a real ability to cause physical operational impact and could be a template for repeatable attacks against Britain’s thousands of smaller energy assets. The episode extends a pattern of Iran-affiliated groups targeting critical infrastructure across the US, Israel, the Gulf, and now Europe since the outbreak of conflict with the US and Israel this year.
Scammers exploit hype around GTA 6, post fake pre-release build to spread malware
A 113GB file circulating on torrent sites and claiming to be a leaked, playable build of the upcoming Grand Theft Auto 6 is fake and bundled with malware, according to users who reverse-engineered it. Nearly all of the file is junk padding wrapped around a small payload that attempts to whitelist the entire system drive in Windows Defender and kill security software outright, giving attackers a foothold on unprotected machines. The scam is riding genuine momentum from an unrelated leaker who has been releasing authentic gameplay footage, making the fake build more convincing to fans eager for early access ahead of the game’s November release.