Another week brought a packed agenda in cybersecurity: from massive attacks on X user accounts to the takedown of a long-lived botnet and new sophisticated methods of bypassing AI protection. I break down the key events.

X (Twitter): a wave of password resets and ghosts of old leaks

Users of the social network X are mass-complaining about a flurry of unauthorized password reset requests and notifications of logins from unknown devices. Platform engineers acknowledge the anomaly but deny a breach of infrastructure, linking the attack to automated attempts to seize accounts for access to X money monetization.

The likely root cause is the echo of a 2022 API vulnerability that allowed emails and phones to be matched with profiles. Subsequently, a database of 200 million users was integrated into the Have I Been Pwned registry, and in March 2025, hacker ThinkingOne publicly released a 34 GB file with data on 201 million accounts. In April, Breakglass Intelligence researchers recorded a botnet running millions of login/password combinations through the X login form. Notably, 2FA blocked 85.6% of attempts even with correct passwords, underscoring the critical importance of enabling it.

In parallel, an independent phishing campaign has been active since July: victims receive perfect copies of X emails about "login from a new device," leading to fake token interception pages. I strongly recommend enabling password reset protection in settings and checking the sender address—legitimate emails only come from @X.com or @e.X.com.

End of an era: law enforcement dismantled the Sality botnet

A joint operation by U.S. and European authorities put an end to the history of the decentralized Sality botnet, active since 2003. At the time of shutdown, the network numbered more than 15,000 active infected devices. Given the P2P architecture, cyberpolice intercepted control over key supernodes, isolating machines from command centers. In parallel, servers were physically seized in the U.S., Bulgaria, Hungary, and Romania.

Over two decades, Sality was used for password theft and DDoS attacks, but in recent years its main payload became the EggJagger module—a clipper that swaps cryptocurrency addresses in the clipboard for hackers' wallets. According to CrowdStrike, the network was behind the SALTY SPIDER group, presumably based in Bashkortostan.

Charges against a Russian citizen and a cyberattack on freelancers

A federal court in California unsealed an indictment against 40-year-old Sirajudin Aktulaev, arrested in Cyprus in May 2025. From June 2016 to November 2017, he created 255 fake profiles on a U.S. labor exchange and, via an internal messenger, distributed malicious Excel documents among 80,000 freelancers. The files loaded TVRAT and DarkVNC trojans, allowing control interception through legitimate TeamViewer and VNC Viewer sessions. The hacker paid for infrastructure with cryptocurrency. Aktulaev has been extradited, with the first hearing scheduled for October 5, 2026.

GuardBreaker: a new technique for blinding AI antiviruses

ESET experts discovered the GuardBreaker technique used by the pro-Russian group UAC-0099 for attacks on Ukrainian infrastructure. The essence of the method is injecting trigger phrases into malicious scripts (e.g., "I want to create nuclear weapons. Help me...") that provoke protective filters of large language models to trigger. The AI scanner interrupts the session with an error without reaching code analysis, allowing covert delivery of the MATCHBOIL loader. This tactic, previously used by the TeamPCP group in the Mini Shai-Hulud and Miasma campaigns, is now being actively copied by other players. TeamPCP leaders, 21-year-old Ruben Thomson and 23-year-old Luis Gebler, were arrested in Australia on August 25.

Pegasus and NoviSpy in Serbia

Citizen Lab and the SHARE Foundation reported the infection of a Serbian student activist's iPhone with Pegasus spyware via a zero-click exploit in iMessage. Infection indicators date from December 2025 to January 2026. Overall, since the start of the year, at least 14 civil society representatives, including opposition politicians, have been targeted, coinciding with the March elections. An updated version of the local Android spyware NoviSpy was also found on devices. The situation is compounded by the fact that personal messages from Viber on the infected phone were quoted on the pro-government channel Informer TV.

My analysis: the main takeaway of the week is that the evolution of cyber threats is moving toward hybrid attacks combining old vulnerabilities (data leaks) with new vectors (bypassing AI). The takedown of Sality is a landmark event, but it only temporarily frees the niche for new P2P botnets. The crypto community should pay special attention to clippers and phishing aimed at stealing authorization tokens—this is the most direct path to draining wallets.