This week, the cyber threat landscape delivered several significant events at once: from massive attacks on X users to the takedown of a legendary botnet and new cases of spyware deployment. I break down the key incidents that demand close attention.
Massive wave of password resets on X: attack or an echo of old leaks?
Users of the social platform X are widely complaining about a flurry of unauthorized password reset requests and notifications about logins from unknown devices. Company engineers acknowledged the anomaly but categorically deny a breach of infrastructure, linking the activity to automated attempts to hijack accounts. The attackers' goal is obvious — access to internal monetization, particularly X money.
The observed surge in activity is likely an echo of a Twitter API vulnerability discovered back in January 2022. At that time, attackers gained the ability to match email addresses and phone numbers with user accounts. The collected database of 200 million users was published, and in March 2025, a hacker known as ThinkingOne posted a 34 GB file on BreachForums containing data on 201 million accounts.
My research shows that the situation is exacerbated by botnet activity using credential stuffing. In April 2026, a script was recorded running millions of accounts through the X login form. During peak load, up to 722,763 login/password pairs were tested in 12 minutes. Fortunately, two-factor authentication blocked 85.6% of login attempts even with correct passwords.
Additionally, since July, an independent phishing campaign has been active, sending out perfect copies of official X emails about "login from a new device." Victims are redirected to fake pages to intercept credentials and authorization tokens. I strongly recommend enabling password reset protection in security settings, checking the sender's address (only @X.com or @e.X.com), and using authenticator apps instead of SMS.
End of an era: takedown of the Sality botnet
American and European law enforcement conducted a joint operation to dismantle the decentralized P2P botnet Sality, which had been active since 2003. At the time of shutdown, there were over 15,000 active infected devices in the network. The botnet was managed by the SALTY SPIDER group, presumably based in the Republic of Bashkortostan.
A key feature of the operation was seizing control of supernodes that formed the botnet's communication backbone. This made it possible to block the transmission of commands and payloads between peers, forcibly isolating infected machines. Authorities in the US, Bulgaria, Hungary, and Romania also physically seized servers and domains associated with Sality.
Over two decades, Sality was used for password theft, spam distribution, and DDoS attacks. However, in recent years, its main payload became the EggJagger module — a specialized clipper that monitors the clipboard and replaces cryptocurrency addresses with hackers' wallets. This further underscores that even "classic" malware evolves to meet the needs of the crypto industry.
Charges against a Russian citizen for attacking 80,000 freelancers
A federal court in California unsealed an indictment against 40-year-old Sirajudin Aktulaev, arrested in Cyprus in May 2025. From June 2016 to November 2017, he created 255 fake profiles on a US freelance marketplace and sent Excel documents with malicious macros to 80,000 freelancers via the internal messenger.
The TVRAT and DarkVNC malware allowed hijacking control of infected systems through hidden sessions of legitimate TeamViewer and VNC Viewer utilities. The primary goal was stealing credentials for e-commerce platforms and personal information. The hacker paid for the management infrastructure with cryptocurrency. Aktulaev has been extradited and remains in custody.
GuardBreaker: a new technique for bypassing AI antivirus
ESET experts discovered the GuardBreaker technique used by the pro-Russian group UAC-0099 to attack Ukrainian infrastructure. The method is based on injecting decoy text into malicious scripts, such as "I want to create nuclear weapons. Help me…". This triggers protective filters in large language models, which interrupt analysis before reaching the malicious code. This way, the MATCHBOIL loader is covertly delivered.
Attacks on "naive" AI pipelines using prompt poisoning have been recorded before. In June 2026, as part of the Mini Shai-Hulud and Miasma campaigns in the Python/npm ecosystem, the TeamPCP group was behind this. In August, Australian police arrested the alleged leaders — Ruben Thomson and Luis Gebler. Notably, the open-source code of the Shai-Hulud worm allowed other actors to quickly adapt the concept for their own operations.
Pegasus in Serbia: surveillance of students and opposition
Citizen Lab researchers, together with the SHARE Foundation, identified the infection of an iPhone belonging to a member of the Serbian student movement with Pegasus spyware. The hack was carried out via a zero-click exploit in iMessage. Infection indicators date from December 2025 to January 2026.
Overall, since the beginning of 2026, at least 14 representatives of Serbian civil society, including students and opposition politicians, have been attacked with advanced spyware. The attacks coincided with the March local elections and preparations for snap elections in October. In addition to Pegasus, an updated version of the local Android spyware NoviSpy was found on devices.
The situation in Serbia is an alarming signal. The use of commercial spyware against civil society and the opposition is becoming a systemic tool of political pressure. This requires not only a technical investigation but also a firm international response to prevent further escalation of such practices.