Security
FBI Charges Five in Russian Murder Plot; Flock Camera Data Exposed
FBI disrupts Russian assassination network, Iranian CHOSEN BRICK malware spreads, and a Parallels bug hands root to any local process on macOS.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
FBI Disrupts Russian Intelligence Plot to Kill Targets on US Soil
Federal authorities unsealed an indictment in Manhattan charging five people, still at large, in a Russian intelligence network that plotted targeted killings in the United States and European nations supporting Ukraine. Prosecutors said the network paid and tried to pay individuals to surveil and murder targets, and recruited associates for terrorism against civilian and military infrastructure. This summer it recruited a US-based person, identified only as U.S. Resident-1, to surveil a prominent Russian dissident, offering $1,000 and $1,500 for the work and $40,000 to eliminate the target. The resident refused. FBI officials said the plot was disrupted through work by multiple field offices and partners.
FBI disrupts Russian plot to carry out targeted killings on US soil, indictment says →
Iran-Linked Hackers Use CHOSEN BRICK Malware Against Dissidents
Government agencies warn that Iranian state-linked hackers are using a Windows malware strain called CHOSEN BRICK to spy on dissidents, activists, and journalists, mainly in the US, UK, and Netherlands. The UK and Dutch cybersecurity agencies published a joint advisory with the FBI. Attacks start with social engineering messages on WhatsApp or Telegram impersonating trusted contacts or tech support, tricking victims into opening files disguised as Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, or KeePass. The malware steals email, Telegram, and WhatsApp data, takes screenshots, records audio, and can wipe the host. Stolen data sometimes appears on pro-Iranian leak sites, increasing physical risk for dissidents abroad.
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets →
KREMLIN Toolkit Installs Malicious Chrome and Edge Extensions
A banking malware operation active since mid-2025 uses a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. Elastic Security Labs found the extensions bypass Chromium integrity mechanisms and load as if approved by the user. Infection begins when a target opens a JavaScript file disguised as a bank receipt, invoice, or business document. After anti-sandbox checks, it downloads Node.js, establishes persistence via a scheduled task, and retrieves the payload location from an Ethereum smart contract. KREMLIN is linked to a Brazilian operation behind at least seven campaigns since May 2025, using lures impersonating 12 banks. Elastic confirmed 1,515 infected systems, almost all in Brazil, and disrupted the campaign.
Malware bypasses browser checks to force install Chrome, Edge extensions →
Hackers Copy Flock Safety Camera Data, Revealing Tracking Details
A hacker collective removed a Flock Safety camera mounted above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED. The data included thousands of videos and logs showing the device captured 1.6 million images of 50,000 vehicles over 21 days. The files reveal in detail how Flock Safety cameras track the movements of both vehicles and people. The hackers say they are publishing details on how they obtained the software, hoping others may copy the method. The disclosure adds to scrutiny of automated license plate reader networks and their retention of detailed location data.
Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works | WIRED →
Parallels Desktop Bug Lets Any macOS Process Gain Root
JFrog Security Research published analysis of CVE-2026-90894, a Parallels Desktop vulnerability letting any user-space process on macOS obtain root privileges without meaningful authentication. The flaw chains three weaknesses: the prl_disp_service socket has 0777 permissions, PrlSrv_LoginLocal accepts peer credentials without verifying a Parallels Team ID signature, and a Qt parser turns a quote in a directory name into executable flags for tar. The CVSS 7.8 flaw was verified on Parallels Desktop 26.4.0 on macOS ARM64, with the injected script gaining NOPASSWD sudoers access. Version 26.4.2 remains vulnerable; only Parallels Desktop 27.0.0 blocks the vector. No in-the-wild exploitation has been reported.
A Quote in a Folder Name Opens Root on Mac: The Parallels Bug | DeafNews →