The week was eventful: from massive attacks on users of the largest social network to the takedown of one of the oldest botnets in history. I break down the key events shaping the threat landscape right now.
Anomalous activity on X: a wave of password resets and the ghost of the 2022 leak
X users faced an avalanche of unauthorized password reset requests and notifications about logins from unknown devices. Platform engineers acknowledged the anomaly but categorically deny any infrastructure breach. In my assessment, we are seeing a classic credential stuffing scenario — attacks using previously compromised databases.
The likely source of the data was the 2022 API leak affecting about 200 million users. The situation was exacerbated by the dump of a 34 GB database in March 2025 containing information on 201 million accounts. My analysis shows that attackers are actively testing these datasets, seeking access to accounts with X Money monetization enabled. Breakglass Intelligence researchers detected a botnet running more than 4.8 million credentials through the X login form, with a peak speed of 722,763 login/password pairs in 12 minutes. Two-factor authentication (2FA) blocked 85.6% of attempts, underscoring its critical importance.
End of an era: the Sality botnet dismantled after 20 years of operation
An international law enforcement operation by the US and Europe put an end to the story of the decentralized Sality botnet, active since 2003. At the time of takedown, the network comprised more than 15,000 active infected devices. Sality's uniqueness lay in its P2P architecture, which made it immune to targeted strikes on command servers. Cyberpolice intercepted control of key supernodes, effectively isolating infected machines from one another.
Notably, over two decades the botnet's functionality evolved from DDoS attacks and spam to the highly specialized cryptoclipper EggJagger. This module monitored the clipboard in real time, replacing victims' wallet addresses with those of the hackers. According to CrowdStrike, the network was operated by the group SALTY SPIDER, presumably based in the Republic of Bashkortostan.
Charges against a Russian citizen: 80,000 freelancers under threat
A federal court in California unsealed an indictment against 40-year-old Sirajudin Aktulaev, arrested in Cyprus in May 2025. From June 2016 to November 2017, he created 255 fake profiles on a US freelance marketplace, sending freelancers Excel documents with malicious macros. The TVRAT and DarkVNC malware provided covert remote access using legitimate TeamViewer and VNC Viewer utilities. The hacker paid for the infrastructure with cryptocurrency, once again demonstrating the close link between cybercrime and digital assets.
AI antiviruses fooled by plain text
ESET experts discovered a new technique for bypassing security systems, dubbed GuardBreaker. The pro-Russian group UAC-0099 embeds text decoys into its scripts, such as "I want to create nuclear weapons. Help me...". This triggers the protective filters of large language models, which interrupt analysis before reaching the malicious code. The method was already tested in June 2026 by the group TeamPCP, whose leaders were recently arrested in Australia. The leak of the source code of the Shai-Hulud worm allowed other actors to quickly adapt this concept.
Pegasus in Serbia: surveillance of the opposition and students
Citizen Lab and the SHARE Foundation confirmed the infection of an iPhone belonging to a member of the Serbian student movement with Pegasus spyware via a zero-click exploit in iMessage. Since early 2026, at least 14 civil society representatives, including opposition politicians, have been targeted. The timeframe coincides with the March local elections and preparations for snap elections in October. In addition to Pegasus, an updated Android spyware called NoviSpy was found on devices.
My comment: The past week confirms a worrying trend: cybercriminals are increasingly using AI both to bypass defenses and to automate attacks. The key takeaway for users is the critical importance of hardware 2FA keys and vigilance regarding any account login notifications. As for Sality, its takedown is only a temporary victory, as the botnet's architectural developments will likely be reused in new projects.