← All news

general

Hacktivist jailed, MEP hit by Pegasus, zero-days dumped

2026-07-04

Some weeks in security don't have one big story, they have twelve small ones that together say quite a lot. This was one of those weeks.

Start in a US courtroom. Aubrey Cottle, a 39-year-old Canadian long associated with Anonymous, was handed 18 months in prison for defacing the Texas Republican Party's website in September 2021 and dumping data he pulled off its server. Four years is a long time to wait for a knock at the door, but hacktivism has a long memory and so does the FBI.

In Japan, telecoms group KDDI disclosed a breach exposing roughly 14.22 million email addresses and passwords across five ISPs, including BIGLOBE, JCOM and NIFTY. A large, unglamorous, painfully useful set of credentials now loose in the wild.

The poisoner, poisoned

The most quietly funny story of the week: Push Security, the firm that first documented the poisoned tenant attack three years ago, got hit with one. Staff received legitimate-looking invitations to join an OpenAI organisation named after their own employer. It works because it looks boring. Administrative emails from real services don't trigger the same reflex as a dodgy PDF from a stranger, which is exactly the point.

Pegasus meets the person investigating Pegasus

Citizen Lab reports that former MEP Stelios Kouloglou was targeted with NSO Group's Pegasus spyware while working on the European Parliament's PEGA committee, whose job was, of all things, investigating Pegasus abuse. No government has been publicly named. Separately, The New York Times reports the September attack that halted Jaguar Land Rover was the work of Russian hackers, with Microsoft, Mandiant, Palo Alto Networks and law enforcement on both sides of the Atlantic drawn into the response.

Zero-days by the dozen

A researcher going by Bikini published proof-of-concept code for dozens of zero-days across widely used open-source projects: FFmpeg, 7-Zip, OpenVPN, VLC, Ghidra, Gogs and Gitea. Nine already have CVEs assigned. The bugs were reportedly surfaced using LLM-assisted fuzzing, and this is probably a decent preview of what the next few years of vulnerability research are going to look like. More bugs, found faster, in places nobody had time to look before.

Jamf also flagged PamStealer, a Rust-based macOS infostealer disguised as the Maccy clipboard manager. It validates stolen credentials through PAM before using them, which is a nice touch of quality control from the malware author.

The ATMs are still bleeding cash

And a reminder that not all cybercrime is remote: two Venezuelan nationals, Carlos Javier Padron and Arnoldo Cabrera Torrealba, were each sentenced to 78 months in a US prison for running a variant of the Ploutus malware on ATMs and walking off with the cash. They owe $1.5 million in restitution, and 96 other people have been charged in connection with the same operation. Cybercrime still has a very physical end, and it still involves standing in front of a cash machine hoping nobody notices.

Hacktivist jailed, MEP hit by Pegasus, zero-days dumped | RiskSense