RSS Amplifier

Rod’s Blog · Aug 17, 2026

Security Check-in Quick Hits: French Tax Breach, SafePal Order Leak, Evooo1Bot Edge Hijacks & China-Linked vCenter Ransomware

0
Sign in to vote or save

Rod Trent · Rod’s Blog

France’s General Directorate of Public Finances confirmed that an attacker gained illegitimate access to internal systems (traced to late June) and extracted data on roughly 678,000 individuals and professionals.

Exposed details include names, addresses, contact info, family quotient, reference tax income, and withholding tax rates for individuals, plus company names and SIREN numbers for businesses. A secondary incident touched cadastral/property records. The threat actor “ZeroBytes” claimed the haul and listed it for sale on a forum; the ministry has notified the CNIL, cut compromised access, and stressed that user login credentials and the public impots.gouv.fr portals themselves were not compromised.

This is classic high-value PII that can fuel targeted phishing, identity theft, or even physical “wrench” attacks against high-income or crypto-holding targets. Organizations and individuals with French tax ties should watch for highly personalized social-engineering attempts.

Crypto hardware-wallet provider SafePal disclosed that an authorization flaw in a third-party order-tracking plugin allowed unauthorized viewing of order records for approximately 39,798 customers who ordered between March 2, 2025, and April 11, 2026.

Leaked data includes names, email addresses, shipping addresses, phone numbers, and purchase details. Critically, seed phrases, private keys, wallet passwords, payment-card data, bank details, and government IDs were not exposed, and SafePal reports no evidence of direct wallet or fund compromise. A threat actor is already offering the dataset for sale, and phishing/impersonation attempts (fake support, firmware updates, etc.) are expected.

SafePal has patched the issue, notified affected customers, shortened data-retention windows, and taken down dozens of related phishing sites. Hardware-wallet buyers should treat any unsolicited contact about their order with extreme skepticism and verify via official channels only.

FortiGuard Labs detailed a previously undocumented Mirai-based Linux botnet family called Evooo1Bot (named after a hardcoded string in its binaries). Active since at least July 2026, it exploits a string of known vulnerabilities in internet-facing edge devices (Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link, and others) to install architecture-matched payloads.

Beyond classic Mirai-style DDoS (16 flooding methods), the malware adds encrypted C2 over port 443, SSH brute-forcing, credential sniffing, a 28-command remote-admin interface, and—most notably—SOCKS5 proxy/relay functionality (direct listener or reverse mode). Compromised routers, cameras, and firewalls become persistent anonymous traffic nodes useful for further attacks or concealment.

Patch edge devices aggressively, disable unnecessary remote management, and monitor for anomalous outbound connections or unexpected proxy listeners.

Researchers (including QUIRSO) attributed active exploitation of the critical VMware vCenter Syslog Server directory-traversal vulnerability CVE-2026-59310 (CVSS 9.8, patched by Broadcom on July 29) to a suspected China-nexus APT. Exploitation began roughly five days after disclosure and has touched hundreds of IPs across dozens of countries.

After initial access the actors deploy reverse-SSH tooling for persistence, perform discovery, and in observed cases drop Babuk-derived ransomware targeting ESXi datastores (partial encryption of large VMDKs). The campaign shows classic post-exploitation tradecraft and rapid weaponization of a freshly disclosed critical flaw.

Any organization running unpatched vCenter instances should treat this as urgent: apply the Broadcom updates immediately, audit for signs of compromise (unusual SSO accounts, reverse shells, datastore activity), and assume internet-exposed management interfaces are under active scanning.

These four stories illustrate the usual mix of large-scale data exposure, supply-chain/authorization weaknesses in consumer tech, opportunistic IoT botnets, and rapid nation-state/APT exploitation of critical enterprise software. Patch, monitor, and treat unexpected outreach with suspicion.

Read the original on rodtrent.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.