TheHatman Listing Major Retail and Hospitality Azure/Entra Records on Dark Web Forum

Executive Summary A threat actor known as TheHatman is currently selling massive internal employee directories belonging to major retail entities on Breached cybercrime forum. Starting on 31 July, TheHatman advertised data dumps allegedly downloaded directly from the organizations’ Azure and Entra portals utilizing compromised credentials. The campaign impacts multiple global retail and hospitality organizations, with the threat…

Read More

DOUBLECUP ClickFix Loader Delivers CountLoader and DeviceManager RATs

Executive Summary A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns. The service enables operators to configure malicious lure pages that instruct victims to copy and execute commands from fake verification prompts. DOUBLECUP retrieves hidden code from a steganographic PNG cached by the victim’s browser…

Read More

The Missing Owner: Why Every AI Agent Needs Governance, Not Just Guardrails

Overnight, a retailer’s support agent issues hundreds of refunds. At a hospitality group, a guest-services agent comps dozens of rooms across the portfolio and reinstates loyalty points to match. Every action clears a standard business rule: valid order or reservation, plausible reason, amount under the threshold that would route it to a human. By morning,…

Read More

NuGet Typosquatting Package Targets Digitain Betting Platform

Executive Summary A JFrog report published on 21 July 2026 detailed a typosquatted NuGet package, Newtonsoftt.Json.Net, that impersonated the legitimate Newtonsoft.Json library. The malicious package delivered a trojanized JSON library designed specifically to manipulate game results within Digitain’s BetOnGames FG-Crash betting platform. JFrog identified seven malicious versions that evolved across three generations, with later versions capable of…

Read More

SharePoint Remote Code Execution Vulnerabilities Enable Server-Side Code Execution

Executive Summary A ThreatLocker report published on 21 July 2026 detailed two critical deserialization vulnerabilities, CVE-2026-50522 and CVE-2026-58644, affecting on-premises Microsoft SharePoint Server deployments. The flaws can allow an authenticated attacker to submit malicious serialized data that is processed by vulnerable SharePoint components, resulting in remote code execution within the SharePoint server context. Successful exploitation could enable command execution, malware…

Read More