Today’s stories are less about a single flaw than about what happens after one — how fast a defender notices, and how far an attacker can automate the follow-through once they’re in. Here’s what’s new since yesterday’s digest.
Detection watch: CISA’s own red team fully compromised one critical infrastructure org while a sibling org caught the intrusion in minutes
CISA published advisory AA26-237A, “A Tale of Two SOCs,” comparing two red team assessments run with near-identical tradecraft against a Government Services and Facilities Sector organization (“Organization A”) and a Water and Wastewater Systems Sector organization (“Organization B”). Against Organization A, the team found a web application still running default credentials on several built-in accounts, used it to send phishing emails from a trusted internal address, landed on four workstations, escalated to domain-wide privileges, and moved laterally into cloud resources — all without detection. Organization B’s defenders spotted the initial compromise quickly and isolated the affected hosts before the team could establish a foothold. Same playbook, opposite outcomes. CISA advisory AA26-237A · The Hacker News
The gap here wasn’t tooling sophistication — it was whether anyone was watching for phishing sent from an internal address and lateral movement off a default-credential web app. Both are cheap to detect if you’re logging for them; neither shows up if you’re not.
Fraud watch: An AI voice-calling phishing service is unlocking stolen iPhones by impersonating Apple Support
Researchers detailed AnonyMousKIT, a phishing-as-a-service platform active since early 2024 that automates stripping Activation Lock from stolen Apple devices. The service pulls a victim’s contact details from the device’s Lost Mode screen, then reaches out by email, SMS, WhatsApp, or an AI voice agent posing as Apple Support across five distinct personas, telling the victim their “missing phone” has been recovered and asking them to confirm their four- or six-digit passcode. Analysts recovered 200 call records and 55 interaction transcripts, and traced the operation to 506 domains feeding 168 reseller storefronts. Beyond unlocking the physical device, a phished Apple ID also opens iCloud backups, synced email and photos, and Keychain-stored credentials. BleepingComputer · The Hacker News
Voice-cloned or scripted-AI “support” calls following a real event (a lost or stolen device, a fraud alert, a password reset) are now cheap enough to run at the scale of a legitimate call center — user awareness training that still frames vishing as rare or amateur-sounding is out of date.
Malware watch: BADBOX-linked malware turns Android car infotainment systems into a residential proxy botnet
Kaspersky documented what it says is the first malware built specifically for automotive head units, found on an Android-based aftermarket infotainment system from Chinese manufacturer DoFun. The threat actor — attributed with high confidence to the MoYu Group, previously linked to the BadBox botnet — exploited a flaw in the device’s built-in update mechanism to push a malicious module called zhima, enrolling the head unit in a residential proxy service that lets other attackers route traffic through it. Google has separately sued BadBox 2.0 operators over a botnet it says already spans more than 10 million Android devices, mostly TV boxes. BleepingComputer · Securelist
Any Android-based device with an internet connection and an update mechanism is a viable botnet node, regardless of what it was designed to do — infotainment systems, TV boxes, and other embedded Android hardware deserve the same “what does this call home to, and can it be verified” scrutiny you’d give a server.
Also noted: 88 documented breaches of identity-verification data have now exposed 2.15 billion confirmed records
A new report tallying identity-verification breaches since 2011 counts 88 separate incidents — 42% of them between January 2024 and August 2026, tracking the rapid global spread of mandatory identity and age-verification checks. In 41 of the 88 incidents, the data exposed included the raw source material itself: ID document scans, verification selfies, fingerprints, and full biometric templates, none of which can be rotated the way a password can. Nearly every major identity-verification vendor of the current era appears somewhere in the timeline, and two national-scale incidents — Argentina’s identity system and France’s ANTS — account for tens of millions of affected people between them. Security Affairs
If your product or vendor chain includes an identity or age-verification step, treat that vendor’s breach history as part of your own risk surface — a leaked selfie or fingerprint template is a liability with no expiration date.
Final thought
Every item today is really the same lesson from a different angle: the controls that mattered weren’t exotic, they were basic ones somebody skipped — default credentials nobody rotated, a support workflow nobody taught to be suspicious of, an update channel nobody locked down, a vendor nobody vetted before handing over a passport scan. If you want a second set of eyes on where your own environment still has one of these gaps, see our how-to guides or book a discovery call.