Skip to content
296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

Ravie LakshmananAug 27, 2026Hacking News / Cybersecurity News

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.

The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different tricks, same advantage: attackers keep finding places where trust is cheap and friction is low.

That sets the tone. Here’s the full list of what surfaced this week.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

  1. Social engineering attempt fails

    Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. The incident took place on August 22, 2026. “The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network,” the company said. “The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.” ReliaQuest said the extent of the access was view only, and that no applications or systems were accessed, and no customer data was ever touched. Although the company did not attribute the incident to a particular threat actor, it noted the playbook aligns with tactics adopted by ShinyHunters and other extortion crews, such as “an impersonation call, a throwaway lookalike domain registered and burned within the hour, a harvesting page behind a content delivery network, MFA push abuse, and a rapid attempt to enroll a new authenticator.” The development comes as ShinyHunters listed the company on its dark web portal. Last week, ReliaQuest said it’s tracking a ShinyHunters campaign using domains that follow the “company[.]claims” pattern, including “reliaquest[.]claims.”

The week’s weirdest detail may be how little separation remains between “advanced” and “ordinary.” Blockchain-backed command channels, AI-assisted botnets, live phishing operators, poisoned software, exposed industrial systems. Different levels of sophistication, often landing on the same old weaknesses.

That is probably the part worth keeping. Attackers do not need every idea to be brilliant. They need one exposed box, one convincing page, one permissive tool, or one person who clicks at the wrong moment. The tooling keeps changing. The openings are often painfully familiar.

That’s it for this ThreatsDay. Patch what matters, question what looks normal, and assume next week will find another cheap way through.

Source link