Log4j Alarm Downsized, 700 Active AWS Keys, and State-Sponsored Threats: Security Week
Ransomware

Illustrative image generated with AI

Log4j Alarm Downsized, 700 Active AWS Keys, and State-Sponsored Threats: Security Week

Security week: Log4j alarm downsized, 700+ AWS keys exposed, ransomware hits, data breach myths, and state threats emerge.

Text generated by artificial intelligence, published without human review. AI transparency

Log4j False Alarm: RCE Possible, but Conditions Are Narrow

The Apache Log4j 2 developers have downplayed reports of a new critical remote code execution vulnerability. A finding about a possible remotely exploitable bug circulated in recent days; the project team confirmed that a path to RCE exists, but described it as a “known non-security finding” and stressed that exploitation requires very specific circumstances. The limited time of volunteers, as the developers noted, could be more usefully spent elsewhere. The shadow of Log4Shell, the vulnerability that shook the industry a few years ago, explains the initial reaction, but this time the residual risk appears contained. No specific mitigations were published; the developers consider the issue a non-finding.

More Than 700 Active AWS Keys and 28,000 Exposed Git Repositories

Truffle Security research identified more than 700 still-active corporate AWS keys that granted full control of accounts. The finding emerged from a review of 10,616 AWS keys exposed between 2022 and 2026. In parallel, Intruder scanned 3.5 million active hosts and found 28,000 exposed Git repositories. These yielded more than 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens, and 17 GitHub personal access tokens. Some of these credentials were still working and could have allowed access to cloud environments, private source code, and sensitive systems. No immediate mitigation measures were disclosed by the companies involved.

Ransomware: LockBit Targets U.S. Bank, Akira Hits Paylogix, Manchester Refuses Ransom

U.S. Bancorp said that ransomware claims citing its name stem from a possible incident at a fourth-party supplier, outside the bank’s environment. The company stated that no compromise of the bank’s systems, networks, or data repositories has been found, even though LockBit threatened to publish data it claims to have stolen. In a separate case, Paylogix said attackers exfiltrated files from its network over several days in November, exposing Social Security numbers, financial and insurance data, medical data, passport numbers, and tax IDs. At least 67,789 people are affected across South Carolina, New Hampshire, and Vermont; the attack was claimed by the Akira group. Manchester Airports Group suffered access to personal data of about 8.7 million customers, including email addresses, phone numbers, vehicle license plates, and postal codes. A ransom was demanded for the return of the data, but the company refused to pay. It said airport operations, passenger safety, and aviation security were not compromised.

Carhartt Breach Downsized: Half of Emails Were Synthetic

Troy Hunt discovered that a large share of the data attributed to the alleged Carhartt breach was actually made up of synthetic TPC-DS benchmark data mixed with genuine customer information. His analysis estimates that about half of the 24.8 million email addresses were fictitious records, significantly reducing ShinyHunters’ initial claims about the amount of real stolen data. The finding warns against the tendency to inflate breach numbers without verifying dataset quality.

Mobile Banking Malware: AI as an Amplifier Against 800 EMEA Apps

Zimperium detected 30 mobile malware families actively targeting more than 800 banking and fintech apps across 44 countries in the EMEA region. The research highlights growing use of artificial intelligence along the attack chain: from localized lures and exploit scripts to more credible phishing pages and overlays. AI allows campaigns to be adapted to local languages and contexts, making attacks harder to recognize. No guidance was provided on how to specifically mitigate this threat.

State Threats: Russian Cyber Training and U.S. Sanctions on Iran

Leaked records from Bauman University reveal a long-running program that trained about 250 students, including career personnel and reservists, for Russian military intelligence and cyber operations. The material covers offensive and defensive techniques, malware analysis, intelligence activities, and military placements; graduates are linked to units associated with the Russian APT28 and Sandworm groups. On the Iranian front, the U.S. Treasury Department sanctioned cyber actors linked to the MOIS, accusing them of compromising critical infrastructure and conducting cyber theft for financial gain. The designated individuals are Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i, accused of intrusions and data theft. Four of the 17 Iranian cyber actors indicted by the FBI were included in the action.

Minimus Shuts Down and Is Acquired by Echo

Minimus, a provider of container image hardening, announced it is ceasing operations after raising $51 million in 2025, saying the economic and investment climate did not allow it to continue. The shutdown comes less than a month after its presence at the Black Hat conference. Shortly after the announcement, Echo said it had acquired the company and its technology.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsLog4jAWS keyscybersecurityransomwaredata breachmobile banking malwarestate-sponsored threats
Back to home