A weekly ThreatsDay round-up notes a miscellany of mischief, from a rogue ransomware affiliate who kept profits for himself to an exposed server containing intrusion tools. The piece highlights that gang betrayals, careless operators, and sloppy design choices continue to let attackers succeed, even when protections exist.
Notable items include a rogue ransomware affiliate publishing stolen data on a private leak site after a multi-country extortion scheme, and an exposed command-and-control setup linked to BraZetsu that had TLS activity on multiple hosts months before disclosure. The overall thread is that both attackers and defenders are stumbling over basic security blind spots, with long-tail consequences that outlive individual campaigns.
Among concrete technical details, the bulletin calls out a range of evolving attacks and supply-chain issues. It references malicious VS Code themes tied to GlassWorm activity, a Windows intrusion chain involving a signed GoFly driver and Vulkan DLL side-loading, and a Power BI phishing campaign that delivers rogue ScreenConnect installers.
A CVE highlighted is CVE-2026-88772, involved in Citrix NetScaler pre-auth exploitation discussion, and a separate note warns of PQC readiness gaps in healthcare devices, with only small percentages capable of supporting post-quantum transitions. Other items describe exposed tooling for Viva Aerobus connections, file-upload flaws enabling web shells, and stealthy npm and RubyGems supply-chain compromises affecting developers.
The piece closes by urging attention to persistent design flaws, exposure of tools, and the need for robust, layered defence as attackers continue to evolve while misconfigurations persist.