Weekly review

ThreatNoir Weekend Brief — August 22

2026-08-22Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — August 22, 2026

The cybersecurity landscape continues to evolve with persistent threats targeting financial institutions, payment systems, and critical infrastructure. Today's briefing covers emerging banking trojans, payment card vulnerabilities, active exploitation of communications platforms, and a sophisticated supply chain attack attributed to state-sponsored actors.

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Three significant banking trojans are commanding attention from threat researchers and security professionals. Manic represents a spyware-equipped threat, while Grandoreiro maintains a persistent campaign targeting victims across Latin America and Europe. ToxicPanda 2.0 has expanded its malware capabilities, indicating an evolution in the threat actor's operational sophistication.

These trojans pose substantial risks to both mobile and desktop users, with their primary focus on compromising financial accounts and stealing banking credentials. Organizations and individuals should remain vigilant regarding phishing campaigns and suspicious email attachments that may deliver these threats. Source: Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Your Expired Visa Card Could Be 'Zombified' to Make Contactless Payments

Security researchers have identified a concerning vulnerability affecting expired Visa cards, which can be exploited to make unauthorized contactless payments through an authentication bypass. This technique, colloquially termed "zombification," allows threat actors to repurpose expired payment cards for fraudulent transactions without proper verification mechanisms.

The discovery highlights critical gaps in contactless payment authentication protocols and raises questions about the security measures protecting financial transactions. Additionally, this week's security news includes reports of Apple issuing an unprecedented number of spyware warnings to users and Ukraine conducting coordinated cyber and drone attacks against a Russian ecommerce platform. Source: Your Expired Visa Card Could Be 'Zombified' to Make Contactless Payments

CISA Orders Feds to Patch Actively Exploited TrueConf Server Flaws

The U.S. Cybersecurity and Infrastructure Security Agency has issued a directive requiring federal agencies to prioritize patching two actively exploited vulnerabilities in TrueConf Server, a self-hosted communications platform. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, allow remote code execution without requiring authentication, representing a critical risk to organizational security.

Threat actors are actively exploiting these vulnerabilities to deploy backdoor malware and gain unauthorized access to affected systems. The urgency of this directive underscores the severity of the vulnerabilities and the immediate threat they pose to federal infrastructure and sensitive communications. Organizations using TrueConf Server should treat patching these flaws as a top priority to prevent compromise. Source: CISA orders feds to patch actively exploited TrueConf Server flaws

Rust Supply Chain Attack Linked to North Korean Hackers

A sophisticated supply chain attack has compromised the Rust programming ecosystem, with evidence pointing to North Korean state-sponsored hackers. The attackers poisoned a popular arrayref crate by introducing a malicious dependency that fetches a payload from a remote server, potentially compromising developers and applications that rely on this widely-used library.

This incident demonstrates the evolving tactics of nation-state actors targeting software development supply chains. By compromising trusted open-source packages, threat actors can distribute malware to thousands of developers and end users without triggering traditional security defenses. The attack highlights the critical importance of supply chain security and dependency management in modern software development practices. Source: Rust Supply Chain Attack Linked to North Korean Hackers

As threats continue to diversify across banking, payment systems, communications infrastructure, and software supply chains, organizations must maintain heightened vigilance and implement comprehensive security measures. Prompt patching, robust authentication protocols, and careful dependency management remain essential components of any effective cybersecurity strategy.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).