SecurityWeek Roundup: Log4j, Minimus, and Sanctions
Weekly roundup covers Log4j RCE scare, Minimus shutdown, Iranian hacker sanctions, and more.
This week’s cybersecurity news saw a familiar name resurface, a security startup pivot overnight, and a fresh round of sanctions against Iranian state-linked hackers. SecurityWeek’s weekly roundup also flagged research into leaked cloud credentials, a mobile banking malware surge, and a breach disclosure that turned out to be partly synthetic. Here’s what you need to know.
Log4j Developers Push Back
An Apache Log4j 2 vulnerability stirred concern this week as reports circulated about a critical remote code execution issue. The library, widely used in Java applications, has been a frequent source of anxiety since the Log4Shell flaw emerged a few years ago.
Log4j developers calmed fears, describing the issue as a “known security non-finding”. They confirmed its potential for remote code execution but pointed out the specific circumstances required for exploitation, and noted that volunteers’ limited time can be spent on more useful things.
The response highlights the tension between security researchers' scrutiny and open-source maintainers' limited capacity. While the severity of this particular issue appears low, the episode is a reminder that Log4j remains a high-profile target.
U.S. Bank Pushes Back on Ransom Claims
U.S. Bancorp says ransomware claims involving its name actually stem from a potential incident at a fourth-party provider, outside the bank’s environment. The bank says there is currently no evidence its systems, networks, or data repositories were compromised.
LockBit has threatened to publish allegedly stolen data, but the bank’s response suggests that even when a ransom demand references a well-known name, the actual source may be several steps removed. This incident underscores the complexity of supply-chain risk in the financial sector.
Minimus Winds Down, Echo Steps In
Hardened container image provider Minimus is shutting down operations after raising $51 million in 2025, citing an unfavorable business and investment climate. The announcement came less than a month after the company appeared at the Black Hat conference.
Shortly after Minimus announced it was winding down, Echo said it acquired the company and its technology. The acquisition signals that even as some startups struggle, their technology still holds value in the security ecosystem.
The Leaked Credential Problem
New research from Truffle Security found over 700 still-active corporate AWS keys that granted full control over their accounts. The discovery was made during the review of 10,616 AWS keys exposed between 2022 and 2026, according to the study.
Separately, Intruder found 28,000 exposed Git repositories while scanning 3.5 million active hosts, uncovering more than 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens, and 17 GitHub PATs. Some credentials were still active and could provide access to cloud environments, private source code, and other sensitive systems.
These numbers illustrate how easily credentials leak into public code repositories. The scale of exposure is enormous, and the potential impact is severe.
Mobile Banking Malware Expands
Zimperium found 30 mobile malware families actively targeting more than 800 banking and fintech apps across 44 EMEA countries. The research also shows attackers increasingly using AI across the attack chain, from localized lures and exploit scripting to more convincing phishing pages and overlays.
The use of AI to craft targeted attacks is a growing concern, as it lowers the barrier for creating convincing social engineering campaigns. This trend is likely to accelerate as AI tools become more accessible.
Carhartt Breach Data Partly Fake
Troy Hunt found that a large portion of the data attributed to the alleged Carhartt breach was actually synthetic TPC-DS benchmark data mixed with genuine customer information. His analysis suggests roughly half of the 24.8 million email addresses were junk records, meaning the original ShinyHunters breach claims significantly overstated the amount of real customer data involved.
This raises questions about the accuracy of breach disclosures. While the alleged breach may still have exposed some real data, the inflated numbers could lead to unnecessary panic and misallocated response efforts.
Paylogix Breach Hits Thousands
Paylogix says attackers stole files from its network over several days in November, exposing Social Security numbers, financial and health insurance information, medical data, passport numbers, and taxpayer IDs. At least 67,789 people have been reported affected across South Carolina, New Hampshire, and Vermont. The Akira ransomware group took credit for the attack.
The range of sensitive data stolen in this breach is particularly concerning, as it could be used for identity theft and financial fraud. The incident also highlights the persistent threat posed by ransomware groups like Akira.
Russian Cyber Training Exposed
Leaked Bauman University records reveal a long-running program that trained roughly 250 career and reserve students for Russian military intelligence and cyber operations. The material covers offensive and defensive cyber techniques, malware analysis, intelligence work, and military placements, with graduates linked to units associated with the Russian threat groups APT28 and Sandworm.
This exposure provides a rare look into how state actors develop their cyber capabilities. The link to known threat groups suggests that these training programs have a direct impact on real-world attacks.
Manchester Airports Group Breach
Hackers accessed personal data belonging to about 8.7 million customers of Manchester Airports Group, including email addresses, phone numbers, vehicle registrations, and postcodes. The attackers demanded a ransom for the return of the data, but MAG refused to pay. The company said airport operations, passenger safety, and aviation security were not affected.
The scale of this breach is significant, though non-payment of ransom is often recommended to avoid fueling further attacks. The impact on affected individuals remains to be seen, but the exposure of contact details could lead to phishing and other scams.
US Sanctions Iranian Hackers
The US Treasury sanctioned Iranian cyber actors tied to the MOIS, accusing the group of compromising critical infrastructure and conducting financially motivated cyber theft. Treasury said Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda’i carried out compromises and data theft, while four of the 17 Iranian cyber actors charged by the FBI were designated in the action.
The sanctions target individuals rather than just state entities, reflecting a trend toward holding individuals accountable for state-sponsored cyber activities. This could complicate the actors' ability to travel and engage in international financial transactions.
Why It Matters
This week’s roundup underscores the persistent and varied nature of cyber threats. From the resurgence of Log4j concerns to the exposure of state-sponsored training programs, the landscape remains dynamic.
For organizations, the credential leak research is a stark reminder that visibility into exposed secrets is critical. For individuals, the breaches at Paylogix and Manchester Airports Group mean that personal data continues to be a high-value target. The Log4j episode, while overblown this time, suggests that even false alarms can cause significant disruption.
Understanding these trends helps security professionals prioritize their defenses. The sanctions against Iranian hackers, the shutdown of Minimus, and the acquisition by Echo all point to a market in flux, where both threats and responses are evolving rapidly.
Sources
- SecurityWeek Original source
- calmed fears Also reporting
- fourth-party provider Also reporting
- acquired the company Also reporting
- study Also reporting
Continue Reading
GiveWP flaw opens server to unauthenticated takeover
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
Cosmos EVM Flaw Exploited After Silent Patch Delay
Six blockchains lost funds in August as a critical Cosmos EVM bug went from no-risk assessment to exploited.
Insider Threat Watchdog Sentenced After Spy Leak Plea
DIA insider-threat IT specialist pleads guilty to leaking top-secret intel to an undercover FBI agent.