Most security messes start as boring admin work. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it.
This week’s ThreatsDay is full of that kind of damage.
Global fraud bust. Operation First Light 2026 — 97 countries, 5,811 arrests, $293 million in illicit assets seized. INTERPOL says over 142,000 victims were identified. In Thailand, police uncovered a romance scam operation that converted funds into crypto using cross-chain token swaps to hide the trail.
Payment SDK typosquats. Socket found 17 malicious npm and PyPI packages typosquatting Paysafe, Skrill, and Neteller SDKs. They steal system info and developer secrets, exfiltrating to an Ngrok endpoint. The malware skips machines with fewer than two CPU cores or sandbox-like hostnames. The obfuscation key changes with every version — no easy signatures to track.
Process Parameter Poisoning. Researchers released a new code injection technique called P³. It uses the Process Parameters structure as a staging location for shellcode — no suspended processes, no suspended threads. Nothing to trigger common detection hooks.
Critical ArcGIS bug. A vulnerability in Esri ArcGIS Server 12.0 and earlier (CVE-2026-9181, CVSS 9.8) lets unauthenticated attackers read sensitive files by sending crafted path parameters. Horizon3.ai found it in the REST Uploads resource — insufficient validation of path traversal.
Ransomware overlaps. New analysis links the Interlock ransomware operation with TAG-124, suggesting shared tooling.
