Security news from the BlueTeamSec community for Wednesday the 12th of August 2026.
Zakir Durumeric published research showing that fewer than 0.2% of domains now have a unique IPv4 address, with millions sharing single IPs. The point is less about the statistic and more about what it means for security policies that still assume one address equals one entity โ turns out collateral damage is rather significant. We've seen related work on favicon-based reconnaissance back in July, which touches on similar infrastructure mapping challenges.
ANY.RUN set up a honey pot targeting North Korean IT workers and documented how Lazarus operatives infiltrate Western companies. They're using AstrillVPN, Vultr infrastructure, and remote access tools to secure legitimate jobs in cryptocurrency and finance sectors โ the goal being payroll fraud plus long-term access to intellectual property. This follows U.S. Department of State alerts on the same workforce scheme from early August, plus recent reporting on North Korean antivirus tooling.
Sonatype found six malicious npm packages, three hijacked and three new, using Ethereum blockchain transactions as a dead drop for command and control infrastructure. The packages are linked to North Korean actors and the 'Contagious Interview' campaign, which targets technical professionals. Worth flagging if you're involved in developer supply chain security โ we've seen a steady run of npm supply chain incidents over the past fortnight, including the QuickFox attack earlier this month.
Hunt Intelligence documented a Russian-speaking toolkit targeting Ukrainian government, military, and e-commerce infrastructure, along with IP cameras across 15 European countries. The operators compromised 58 cameras for surveillance, used custom scripts and tools like Ingram for credential brute-forcing, and repurposed devices as SOCKS5 proxies. Activity was observed in May and July, and the tradecraft includes headless browsers to evade anti-bot controls. This sits alongside earlier reporting on Russian webmail espionage and the Midnight Blizzard campaign from late July.
CISA published a ransomware advisory on Gunra, a ransomware-as-a-service operation active since April 2025 that's been hitting multiple critical sectors with double-extortion tactics. They're exploiting vulnerabilities in FortiOS and FortiProxy, among other internet-facing devices. The Linux variant has a cryptographic weakness in its pseudorandom number generator, which may allow file recovery without paying. One for incident responders dealing with Gunra infections โ and adds to the fairly busy ransomware landscape we've been tracking this month.
That's everything for today from BlueTeamSec. Attribution sits with the original authors โ the analysis here was automated.