TL;DR
Android car head units are being compromised via legitimate updaters to form proxy botnets; AWS has 9,300+ leaked access keys still active; a Canadian cybercriminal pleaded guilty in the Snowflake extortion campaign affecting 165+ organizations.
Executive Summary
- Android-based vehicle head units are being infected through trojanized firmware updates, enabling proxy botnet operations and ad fraud.
- Over 9,300 AWS access keys exposed between August 2022 and August 2026 remain active and valid, granting full account control.
- Connor Riley Moucka, 26, pleaded guilty to extorting 165+ organizations via Snowflake, marking a significant enforcement win in cloud data theft.
- Ongoing: RedC2 npm supply-chain attack and Microsoft Defender driver weaponization remain under active investigation.
Top Threats Today
1. Android Car Head Unit Compromise via Supply Chain
Severity: HIGH Affected: Transportation
Cybersecurity researchers have identified a new malware family targeting Android-based vehicle head units manufactured by DoFun ⚠[1]. The attack leverages the device's built-in updater application to distribute malware that enlists compromised vehicles in a proxy botnet or redirects traffic for ⚠ ad fraud [2]. Kaspersky discovered the threat in June 2026 [1]. The malware exploits a legitimate supply-chain vector – the device firmware update mechanism – making it particularly difficult for end users to detect [2].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Audit vehicle head unit firmware versions and update status across your fleet management systems.
- Restrict vehicular network access to known-good traffic patterns and monitor for unexpected proxy or ad-serving traffic.
- Contact device manufacturers for security advisories and patched firmware versions.
- Consider network segmentation to isolate in-vehicle systems from corporate or sensitive data networks.
2. AWS Credential Exposure: 9,300+ Active Keys Still in Circulation
Severity: HIGH Affected: Technology
More than 9,300 Amazon Web Services access keys publicly exposed between August 2022 and August 2026 remain active and valid [1]. These leaked credentials grant attackers full control over associated corporate AWS accounts, representing a persistent and active threat to organizations that have not rotated their keys [1].
Sources:[1] BleepingComputer
Recommended Action
- Conduct an immediate audit of all AWS IAM access keys to identify any created outside your standard provisioning process.
- Rotate and revoke any access keys that may have been publicly exposed or are older than your organization's key rotation policy.
- Enable CloudTrail logging and review access key usage patterns for any suspicious activity.
- Implement AWS access key management policies that enforce automatic rotation and restrict key lifetime.
3. Snowflake Extortion Campaign: Canadian Threat Actor Pleads Guilty
Severity: HIGH Affected: Finance
Connor Riley Moucka, 26, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy in connection with hacking and extorting more than 165 organizations that used the Snowflake cloud data storage platform [1]. Moucka was previously described as one of the most consequential cybercrime threat actors of 2024 [1]. This guilty plea represents a significant enforcement action against a high-impact threat actor and provides law enforcement visibility into the scale and scope of Snowflake-targeted extortion campaigns.
Sources:[1] Krebs on Security
Recommended Action
- Review Snowflake account access logs and activity records for any unauthorized data access or exfiltration during the suspected compromise window (2024 onward).
- If not already done, implement multi-factor authentication and IP allowlisting on all Snowflake accounts.
- Consult with Snowflake support to confirm whether your organization was among the 165+ victims and determine what remediation is required.
- Monitor darkweb and underground forums for any indication that your organization's data was accessed or threatened.
4. Microsoft Teams Phishing: SynkLoader Malware Campaign
Severity: HIGH Affected: Technology
A previously unknown malware family dubbed SynkLoader is being distributed via phishing campaigns on Microsoft Teams [1]. The malware steals credentials by displaying a fake lock screen to users [1]. This attack exploits trusted internal communication channels and represents a notable shift toward targeting employee identity and credential theft.
Sources:[1] BleepingComputer
Recommended Action
- Deploy security awareness training focused on Teams phishing, including the risks of clicking suspicious links or visiting non-standard authentication pages.
- Enable advanced threat protection in Microsoft Teams to detect and quarantine phishing messages.
- Enforce MFA across all Microsoft 365 accounts to reduce credential theft impact.
- Monitor for suspicious Teams activity, including unusual message forwarding or profile changes.
Today’s Action Checklist
- ☐ URGENT: Audit and rotate all AWS access keys; verify none of the 9,300+ exposed keys belong to your organization.
- ☐ HIGH: Review Snowflake access logs for indicators of compromise; confirm MFA and network controls are in place.
- ☐ HIGH: Patch or isolate Android-based vehicle head units; request firmware security updates from manufacturers.
- ☐ HIGH: Conduct targeted phishing awareness training on Microsoft Teams social engineering and credential theft tactics.
- ☐ Monitor CISA KEV and vendor advisories for patches to TrueConf Server (CVE-2026-72529, CVE-2026-72530) and Zimbra (CVE-2026-73570).