Security news from the BlueTeamSec community for Thursday the 27th of August 2026, with seven stories to get through.
Politico report that state-sponsored actors are running spearphishing campaigns against high-ranking EU officials across politics, diplomacy, and military sectors, targeting messaging accounts on WhatsApp and Signal. The attackers are using fake support chatbots and personalised social engineering, and EU cyber defence units have officially attributed the activity to foreign governments — eight significant incidents confirmed this year alone.
Allsecure have traced a North Korean campaign targeting macOS users through malvertising that tricks victims into pasting malicious terminal commands. The operation uses Ethereum smart contracts for command and control, deploys infostealers aimed at cryptocurrency wallets, and has already laundered around 890,000 dollars — which is either impressive tradecraft or a sign that people are still clicking paste without reading what's in the clipboard.
The US Attorney's Office for Nebraska announced an eight-year sentence for a Venezuelan national involved in an ATM jackpotting conspiracy linked to the Tren de Aragua transnational criminal organisation. The attackers deployed malware to force cash dispensing from machines across 47 states and foreign countries, with 119 defendants charged in Nebraska alone — the revenue reportedly funded trafficking and violent crime.
CISA published results from red team assessments on two organisations in the government services and water sectors — both ended in full domain compromise and access to sensitive business and cloud systems. The findings show that defensive tools were present but rendered ineffective due to poor implementation and organisational friction, which is a recurring theme in these exercises.
A CYBERUK 2026 presentation outlines how to justify security investments using triangulated evidence from insurance claims, forensic reports, and vendor studies. Key takeaways: phishing-resistant MFA is twice as effective as basic MFA, legacy VPN appliances increase breach likelihood five to ten times, and EDR in blocking mode doubles risk reduction compared to basic deployment — one for those building business cases.
The Objective-See Foundation have written up how advanced adversaries are using malicious dynamic libraries on macOS to inject code into legitimate processes. The technique allows attackers to inherit the host process's privileges and access to protected resources while evading process-level detection — particularly relevant if you're defending macOS environments.
And finally, Airbus released Ditto, an open-source obfuscator for PowerShell and JavaScript built on tree-sitter parsers. It's designed for red teamers and security researchers to test detection systems against obfuscation techniques like string encoding, identifier renaming, and control flow transformation — a defensive tool that helps you see what your detections might be missing.
That's all for today. The articles are the work of their original authors — the analysis here was automated.