Vista elenco

Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam

13 Agosto 2026 ore 15:10

Security researchers have identified a phishing campaign that abuses Shopify’s own Shop app to deliver fake order and refund notifications directly to victims’ phones, marking a notable evolution of the classic “fake refund” scam.

According to research from cybersecurity firm Huntress, attackers are creating fraudulent Shopify seller accounts, or hijacking legitimate ones, to generate bogus orders against victims’ phone numbers or email addresses. Because Shopify’s Shop app treats these as genuine transactions, targets receive real push notifications and in-app receipts, rather than a suspicious email or text from an unfamiliar sender. Huntress said several of its own employees were targeted between May and August 2026, and that the technique has also been documented by researchers at Gen Digital and reported by users on Reddit.

In one example cited by Huntress, a fake receipt dated 7 August billed the recipient $339.96 for a “premium PC protection plan,” complete with a fabricated invoice number and transaction ID. The real sting sits in the shipping address field, which attackers repurpose to display a message urging the recipient to call a phone number if they did not place the order. Some variants dispense with the fake address altogether and instead push recipients toward the number via the order description, while others add a spoofed “out for delivery” shipment tracker to increase pressure on the target.

Victims who call the number are funnelled into a standard refund scam. Huntress said callers are typically talked into installing remote access tools such as ScreenConnect or AnyDesk, or into logging into their online banking. From there, scammers manipulate on-screen figures, sometimes editing displayed transaction details or coaching victims to misread a refund amount, to convince them they were mistakenly overpaid. Victims are then pressured to “return” the difference, usually by purchasing gift cards and handing over the redemption codes, which attackers cash out quickly.

Huntress frames the campaign as a variant of a technique it calls Living off Trusted Sites (LoTS), where attackers route victims through a legitimate, trusted platform before reaching a malicious outcome, rather than relying on a fake domain that is easier to flag. While earlier LoTS attacks used links to services such as Dropbox, Canva, or DocuSign to add credibility, this campaign instead abuses Shopify’s own notification pipeline to generate content that looks and functions exactly like a native alert. The firm noted a similar pattern in a previous campaign involving genuine PayPal invoices carrying fraudulent callback numbers.

Shopify has acknowledged the scam in its Help Center. The company and Huntress both advise users not to interact with unfamiliar phone numbers, email addresses, or links found within an order, and to contact Shop Support directly if they are concerned about the security of their account. Users who receive a suspicious order notification are advised to check their bank statements before assuming any charge went through, and can flag the order as “Not my order” within the Shop app. Huntress also recommends checking a store’s reviews and history before purchasing, noting that many of the fraudulent shopfronts used in this campaign were newly created.

The post Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam appeared first on IT Security Guru.

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

13 Agosto 2026 ore 13:59

An affiliate of the Akira ransomware operation attempted a novel technique to blind endpoint defences during a recent intrusion, rebooting a compromised server into Windows Safe Mode to knock out both an EDR agent and Microsoft Defender in one move, only for the same stripped-down environment to cause the ransomware payload itself to crash before it could encrypt any files.

The incident, disclosed in a technical write-up published by managed detection and response provider Huntress, marks the first time researchers have observed Akira affiliates using a Safe Mode reboot to sidestep security tooling, a tactic more commonly associated with older ransomware families such as Snatch and AvosLocker.

Akira has been one of the most active ransomware operations tracked by Huntress over the past year, and its affiliates typically follow a consistent playbook: break in through an internet-exposed VPN appliance, most often from SonicWall, move laterally to the domain controller, enumerate Active Directory, exfiltrate data, and detonate the encryptor within a matter of hours. This latest attack followed that pattern almost exactly, according to Huntress, but introduced a twist at the final stage.

Credential Spray, No MFA, and a Familiar Path to the Domain Controller

According to Huntress, the intrusion began in early August with a burst of failed login attempts against a SonicWall SSL VPN, consistent with a credential-spraying attack. Roughly seven minutes later, one attempt succeeded: a valid VPN account with no multi-factor authentication in place. Nearly two hours passed before the attacker took hands-on action, logging into the domain controller over RDP and running PowerShell commands to dump full property details on every user and computer in the Active Directory environment, reconnaissance Huntress says is a hallmark of Akira intrusions.

The attacker then moved to an application server, installed WinRAR to archive mapped file shares, and used the S3 transfer tool s5cmd to upload the staged data to a cloud storage bucket under their control, standard double-extortion tradecraft designed to give the attacker leverage even if a victim can recover from backups. AnyDesk, a legitimate remote access tool, was installed as a persistent service and used both for hands-on-keyboard control and to deliver the ransomware payload itself.

The Safe Mode Gambit

Rather than spinning up a separate virtual machine to run the encryptor outside the reach of security software — a method Huntress has documented in earlier Akira cases- the affiliate instead used the built-in Windows configuration tool msconfig.exe to force the host to reboot into Safe Mode with Networking. Because Safe Mode loads only core Windows drivers and disables most third-party software by design, the reboot simultaneously took the Huntress agent offline and prevented Microsoft Defender’s real-time protection from starting, all while preserving the network connectivity the attacker needed to keep working.

The attacker had anticipated that Safe Mode would also block their own AnyDesk service, and pre-emptively added a registry entry to keep it running through the reboot, a detail Huntress says shows deliberate planning rather than an improvised move.

The Ransomware Undermined Itself

The plan worked well enough to blind defences, but it also appears to have doomed the attack. Minutes after the akira.exe payload launched, the host began throwing “out of virtual memory” errors, and the ransomware process tree failed before encryption could begin. Huntress attributes the crash to Safe Mode’s constrained memory environment, which was seemingly unable to support the ransomware’s resource demands.

A scheduled Defender scan eventually flagged the payload roughly an hour later, correctly identifying it as Akira, but could not quarantine it because real-time protection remained disabled in Safe Mode. The file was only removed after the attacker rebooted the host back into normal operation, restoring Defender’s protection in the process, meaning the attacker’s own anti-EDR trick was undone by their need to reverse it.

Despite the failed encryption, the attacker had already exfiltrated Active Directory data and file shares before the reboot, leaving the victim exposed to extortion even without any files being locked. Huntress cautioned that the outcome should not be read as a reliable defence: a host with more memory or a larger page file might allow the encryptor to succeed in Safe Mode, and researchers said it is plausible Akira’s developers will adjust the malware’s memory footprint or boot sequence to make the technique more reliable in future attacks.

Recommendations

Huntress urged organisations to enforce MFA on all VPN accounts, monitor for bursts of failed VPN logins followed by a successful one, and ensure EDR is deployed across every endpoint rather than a subset of the environment. It also recommended that defenders specifically alert on boot-configuration changes and Safe Mode reboots, including msconfig.exe and bcdedit activity, and Windows event log entries indicating a Safe Mode boot as well as any modification to the registry keys that control which services are permitted to run in Safe Mode.

The post Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack appeared first on IT Security Guru.

Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks

13 Agosto 2026 ore 13:04

Forescout has launched a new Rapid Insight Assessment designed to help organisations uncover hidden assets, network blind spots, and security exposures as artificial intelligence accelerates vulnerability discovery.

The new assessment combines external analysis with passive network monitoring to give security teams a clearer picture of their attack surface. Forescout says the service can deliver actionable findings within days, helping organisations identify and prioritise risks before attackers exploit them.

The launch comes as security teams face the challenge of managing increasingly complex environments. Unmanaged devices, shadow assets, exposed services, and gaps in network visibility can all create opportunities for attackers.

At the same time, advances in AI are making it possible to discover and exploit vulnerabilities faster.

Finding security exposures before attackers do

The Rapid Insight Assessment uses open-source intelligence to examine an organisation’s external exposure. For internal assessments, Forescout can also deploy its portable Flyaway Kit to passively observe network activity without disrupting operations.

The Flyaway Kit provides visibility across IT, OT, IoT, cyber-physical systems, and unmanaged devices, including assets within remote and air-gapped environments.

The assessment can identify internet-facing remote access services, exposed administrative interfaces, previously unknown network devices, risky communications, and unmanaged OT and IoT assets.

It can also provide more detailed asset intelligence and identify devices associated with Known Exploited Vulnerabilities.

AI is shrinking the window for defenders

Craig Weimer, Vice President and General Manager of Americas at Forescout, said the increasing ability of AI systems to carry out cyber tasks is changing how quickly organisations need to identify security weaknesses.

“When an AI system can discover, connect, and exploit vulnerabilities on its own, the idea of an autonomous attacker is no longer just a future concern,” Weimer said.

He pointed to recent public disclosures from OpenAI, Anthropic, and Meta showing that frontier AI models can perform complex, multi-step cyber tasks against real environments with limited human involvement.

“The message for defenders is clear: the window between exposure and exploitation is getting smaller, and organisations need a complete understanding of their attack surface before adversaries find it first,” he added.

Tackling network blind spots

One of the challenges facing security teams is that they cannot protect assets they do not know exist. This becomes particularly difficult across large or distributed environments where new devices and services can appear without being captured by existing security processes.

Forescout says its Rapid Insight Assessment is intended to provide organisations with a faster way to uncover these gaps without lengthy assessment cycles.

“Organisations can’t afford assessment cycles that take months when hidden exposures, network blind spots, and unknown assets can quickly become opportunities for attackers,” Weimer said.

“The Rapid Insight Assessment gives organisations a fast, efficient way to see their most critical security risks and exposure gaps, delivering clear, actionable findings in days so they can address exposures before they become security incidents.”

As AI gives attackers greater speed and automation, gaining an accurate view of the attack surface could become increasingly important. For defenders, finding hidden exposures before an adversary does may prove critical to reducing the opportunity for an attack in the first place.

Learn more and request your free Forescout Rapid Insight Assessment.

The post Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks appeared first on IT Security Guru.

UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally

13 Agosto 2026 ore 12:57

UK organisations were hit by an average of 1,597 cyber attacks per week each in July 2026, a 26% increase year-on-year, according to new data from Check Point Research, the threat intelligence arm of Check Point Software Technologies. The growth rate outpaced the 16% year-on-year rise recorded globally, even though UK attack volumes remained below the worldwide average of 2,336 weekly attacks per organisation.

The figures form part of Check Point Research’s Global Threat Intelligence report for July 2026, which found that cyber risk is accumulating across multiple fronts at once: rising attack volumes, a sharp acceleration in ransomware activity, and growing exposure from the use of generative AI tools in the enterprise.

In the UK, Education, Energy & Utilities, Software, Government, and Media & Entertainment were named as the five most targeted industries in July, reflecting attackers’ continued focus on sectors that hold sensitive personal data, run critical national infrastructure, or present broad, distributed attack surfaces.

Global attacks keep climbing

Worldwide, organisations faced an average of 2,336 weekly cyber attacks in July, up 3% month-on-month and 16% year-on-year. Education remained the most targeted sector globally, averaging 4,848 weekly attacks per organisation, up 14% year-on-year. Government followed with 3,044 attacks and Telecommunications with 2,927, while Energy and Utilities rose 20% to 2,759 attacks and Hospitality, Travel and Recreation entered the global top five with 2,614 attacks, up 28%, likely reflecting increased exposure during the summer travel period.

Regionally, Latin America recorded the highest attack volume, with 3,561 weekly attacks per organisation, up 19% year-on-year, followed by APAC at 3,316. Europe stood out for its rate of growth, with attacks up 18% year-on-year to 2,051 per organisation, ahead of North America’s 9% rise to 1,613.

Ransomware breaks from its earlier pattern

The sharpest shift in July came from ransomware. Reported victims reached 964 globally, up 87% year-on-year and 49% from June, marking a decisive break from the first half of 2026, when monthly ransomware activity averaged around 672 incidents. Business Services was the most affected sector, accounting for 32.5% of reported victims, followed by Industrial Manufacturing at 14.4% and Consumer Goods and Services at 13.4%.

North America remained the most affected region for ransomware, accounting for 45% of reported incidents, followed by Europe at 28% and APAC at 17%. At country level, the United States continued to dominate the victim count with 39.4% of reported attacks, followed by Germany, Canada, the United Kingdom and Italy.

The Gentlemen and Qilin were the most prevalent ransomware groups in July, each responsible for 14% of published attacks, while DeadLock climbed to third place with 10% and 97 reported victims, highlighting continued churn in the ransomware ecosystem.

GenAI exposure becomes a daily business risk

The report also highlighted the growing data exposure risk posed by generative AI tools. One in every 36 prompts sent from enterprise networks carried a high risk of sensitive data leakage, and 88% of organisations that regularly use GenAI tools were affected by high-risk prompt activity. Organisations used an average of eight GenAI tools in July, with individual users generating 95 prompts on average during the month.

Personal data was the most common sensitive category exposed, appearing in 70% of organisations, followed by financial data and network and IT infrastructure information, each present in 68% of organisations.

Email also remained a high-volume risk channel: one in every 128 emails, or 0.78%, was classified as phishing in July, with a further 20% falling into unwanted or risky categories such as graymail, spam and suspicious messages.

“Cyber risk is accumulating across multiple fronts”

“July’s data shows that cyber risk is accumulating across multiple fronts at once,” said Barnaby Nickels, regional sales manager for UKI & North EU at Check Point Software. “Attack volumes continue to rise, ransomware has accelerated sharply, and GenAI exposure is now part of daily business activity. Organisations need prevention-first, AI-driven security that protects networks, users, data and AI workflows before attacks can cause impact.”

For UK organisations, the message lands with particular urgency. With attack growth outpacing the global average and sectors ranging from education to critical infrastructure squarely in attackers’ sights, security teams are being urged to strengthen defences across network, cloud, endpoint, email and AI usage rather than relying on any single layer of protection.

The post UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally appeared first on IT Security Guru.

❌