Lab539 Uncovers WordPress Campaign Utilizing PowerShell RAT to Target Entities

Executive Summary Researchers from Lab539 on 12 August 2026 observed a widespread campaign utilizing compromised WordPress sites to deliver a ClickFix verification flow that prompts users to execute a malicious PowerShell command. The injected JavaScript employs an EtherHiding mechanism, retrieving AES-encrypted code from an Ethereum smart contract on the Sepolia network rather than hardcoding the payload…

Read More

When Your Vendor’s Vendor Goes Down: What a Logistics Incident Teaches Retailers About Fourth-Party Risk

A Single Incident Ripples Across Industries In late July, a major global logistics and shipping provider was hit by a cyberattack that disrupted warehouse operations across Europe. The company, which operates more than 1,700 facilities in 170 countries, notified affected customers in early August that several European warehouses were unable to ship stored goods. Some…

Read More

Zombie Card Attack Exploits Contactless Payments for POS Terminals

Executive Summary Researchers at the University of Massachusetts Amherst report the technical details of an attack vector that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale terminal reads over near-field communication, without breaking any of the card’s cryptography. The attack, which the researchers named Zombie Card, requires physical…

Read More

When Your Vendor’s Vendor Goes Down: What a Logistics Incident Teaches Retailers About Fourth-Party Risk

A Single Incident Ripples Across Industries In late July, a major global logistics and shipping provider was hit by a cyberattack that disrupted warehouse operations across Europe. The company, which operates more than 1,700 facilities in 170 countries, notified affected customers in early August that several European warehouses were unable to ship stored goods. Some…

Read More

TheHatman Listing Major Retail and Hospitality Azure/Entra Records on Dark Web Forum

Executive Summary A threat actor known as TheHatman is currently selling massive internal employee directories belonging to major retail entities on Breached cybercrime forum. Starting on 31 July, TheHatman advertised data dumps allegedly downloaded directly from the organizations’ Azure and Entra portals utilizing compromised credentials. The campaign impacts multiple global retail and hospitality organizations, with the threat…

Read More