- Services
- Products
- Compliance
- Markets
- Insights
- About
Threat Intel Update
This week’s reporting points to a clear trend: attackers are exploiting trusted users, software, and business processes to reach sensitive data and systems.
Ransomware operators are now targeting managers with access to financial, HR, and operational functions, not just executives or IT admins. Researchers also found a fake Zoom installer that quietly drops a remote access trojan alongside the real app.
Separately, newly disclosed Zoom vulnerabilities could have let attackers compromise meeting participants with zero user interaction before patches shipped. And a new threat called GhostSplice showed how malicious MCP servers can manipulate AI coding assistants into leaking sensitive data.
The takeaway: strong access controls, software validation, timely patching, and caution with AI tools all matter more than ever.
Cybersecurity News
- Ransomware Shifts Target: Mid-Level Managers Over Executives – Zscaler tracked 351 victims in a single monthly campaign and found attackers deliberately targeting manager-level employees (average age ~46) with business-process access, not technical admins. Nearly two-thirds of victims held manager titles, and three-quarters worked in finance, HR, sales, ops, or marketing. This exposes a gap in privileged-access models built around IT admins rather than staff who approve payments or manage budgets. Ransomware attempts rose 146% year-over-year, with public extortion up 70% and stolen data up 92%. The Register
- Fake Zoom Installer Delivers Cross-Platform RAT – Jamf Threat Labs found a fake Zoom installer that quietly deploys the Overlord RAT while also installing the real Zoom app to avoid suspicion. Using a .NET-based downloader, it targets both macOS and Windows from one codebase. Overlord RAT enables keylogging, screen/webcam/mic access, file control, and remote desktop, and went undetected by VirusTotal at the time of analysis. It also uses a blockchain-based resolver to find command servers, making takedowns harder. Hack Read
- GhostSplice: Malicious MCP Servers Trick AI Coding Assistants – ASSET Research Group disclosed GhostSplice, a technique that splits a data-theft instruction across multiple MCP channels so no single piece looks malicious. Compliance rates jumped from 42% to 82% across 15 tested models when requests were fragmented. Any AI coding assistant connected to a third-party MCP server is at risk, no special access needed beyond what the agent already has. At-risk data includes SSH keys, env files, and source code; results varied significantly by client, not just by model. The Hacker News
- FBI Warns of Account Hijacking for Sextortion Schemes – The FBI warned that criminals are hijacking social media accounts to steal explicit images/videos from both adults and children, with student-athletes specifically flagged alongside the NCAA. Stolen content and personal data (names, DOBs, contacts) are sold on criminal marketplaces, then used by other actors to extort victims further, fueling ongoing harassment and stalking. BleepingComputer
- Zoom Patches Zero-Click Flaws in Annotation Feature – Zoom fixed three memory-corruption bugs (CVE-2026-53413/53414/53415) in its annotation tool that let any meeting participant compromise another attendee’s client with zero interaction. A presenter could have compromised all viewers, or vice versa, with no visible sign of attack. Fixes shipped in June-July 2026, ahead of public disclosure; no known exploitation or CISA KEV listing to date. The Hacker News
Sign Up
To receive Threat Briefings by email.