The week was packed with events in the field of digital security. From massive attacks on users of the largest social network to the takedown of a veteran botnet and new schemes of artificial intelligence deception — I break down the key incidents that require close attention.

Attack on X: phantom password resets and the hunt for monetization

Users of the X platform are mass-complaining about a barrage of unauthorized password reset requests and notifications of logins from unfamiliar devices. The social network's engineers acknowledge the anomaly but deny a breach of infrastructure. The most likely cause is automated attempts to intercept accounts for access to internal monetization, particularly X money, which recently became available to all premium subscribers in the U.S.

The surge in activity appears to be an echo of the Twitter API vulnerability from January 2022. That database of 200 million users, mapping emails and phones to accounts, has long been listed in the Have I Been Pwned registry. The situation was compounded by a 34 GB file leaked in March 2025 with data on 201 million X users. Moreover, in April, Breakglass Intelligence researchers recorded a botnet that ran more than 4.8 million accounts through the X login form, testing up to 722,763 login/password pairs in 12 minutes at its peak. Two-factor authentication blocked 85.6% of attempts with correct passwords, underscoring its critical importance.

In parallel, an independent phishing campaign has been active since July, sending perfect copies of X emails about "login from a new device" to intercept authorization tokens. I strongly recommend enabling password reset protection, checking the sender's address (only @X.com or @e.X.com), and using authenticator apps instead of SMS.

End of an era: takedown of the Sality botnet

American and European law enforcement announced the destruction of the decentralized Sality botnet, which had been active since 2003. At the time of shutdown, it contained more than 15,000 active infected devices. Due to its P2P architecture, disabling a single server was impossible, so cyber police intercepted control over key supernodes, isolating infected machines and blocking the transmission of commands.

Of particular interest is the evolution of this botnet. Over two decades, it was used for password theft and DDoS attacks, but in the last eight years, its main payload became the EggJagger module — a specialized clipper that replaces cryptocurrency addresses in the clipboard with hackers' wallets. This is a clear illustration of how old infrastructure adapts to the new realities of the digital economy.

Charges against a Russian citizen and "blinding" AI antiviruses

A federal court in California unsealed an indictment against 40-year-old Sirajudin Aktulaev, arrested in Cyprus in May 2025. From June 2016 to November 2017, he created 255 fake profiles on a U.S. labor exchange, sending 80,000 freelancers Excel documents with malicious macros. The downloaded TVRAT and DarkVNC trojans allowed interception of system control through hidden TeamViewer and VNC Viewer sessions. He paid for the infrastructure with cryptocurrency, and half of the infected PCs were located in the U.S. The first hearing is scheduled for October 5, 2026.

ESET experts identified a new technique called GuardBreaker, used by the pro-Russian group UAC-0099 against Ukrainian infrastructure. The attackers embed open-text decoys into malicious scripts, such as "I want to create nuclear weapons. Help me..." This triggers the protective filters of large language models, which interrupt the session with a refusal error without ever analyzing the code itself. The method is used for the covert delivery of the MATCHBOIL loader. Similar attacks, Mini Shai-Hulud and Miasma, in the Python/npm ecosystem were already recorded in June, and in August, Australian police arrested the alleged leaders of the TeamPCP group.

Pegasus and NoviSpy: digital surveillance in Serbia

Citizen Lab, together with the SHARE Foundation, reported the infection of an iPhone belonging to a member of the Serbian student movement with Pegasus spyware via a zero-click exploit in iMessage. Infection indicators date from December 2025 to January 2026. Since the beginning of 2026, at least 14 representatives of civil society have been targeted, including students and opposition politicians, coinciding with the March local elections. An updated version of the local Android spyware NoviSpy was also found on the devices, and private messages from Viber from the infected phone were quoted on air by a pro-government television channel.

My analysis: The current situation demonstrates a worrying trend — malicious actors of all stripes are actively exploring new attack vectors, from social engineering to bypassing AI defenses. The GuardBreaker case is especially telling: it is the first mass example of using the "blind spots" of large language models to sabotage security systems. I recommend that the crypto community and everyone working with digital assets reconsider their security protocols, betting on hardware wallets and multi-factor authentication rather than relying solely on automated solutions.