Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (29 May 2026)
Published: Loading…
At a Glance
- Reservation Hijack scams used compromised reservation data across 350 accommodations in 50 countries to direct travellers to fraudulent payment verification pages and steal booking-linked credentials.
- FBI warned cyber actors are spoofing FIFA websites using typosquatting domains such as fifa[.]cab and fifa-2026[.]xyz to harvest financial and personal data ahead of World Cup ticket sales.
- Carnival Corporation confirmed a breach affecting nearly six million customers after attackers used social engineering against an employee account and accessed personal and identity data.
- A malicious Sicoob.Sdk NuGet package exfiltrated banking certificates and credentials via a hardcoded Sentry endpoint, enabling impersonation of Sicoob financial APIs.
- A self-propagating Go-based Gentlemen ransomware strain used Curve25519 encryption and lateral movement tools including PsExec and WMI to spread across enterprise networks.
- North Korea-linked Sapphire Sleet deployed macOS malware via fake Zoom SDK updates, abusing AppleScript and LaunchDaemons for persistence and credential theft.
Summary
Reservation-linked phishing operations expanded across travel ecosystems with Reservation Hijack scams targeting 350 accommodations across 50 countries. Attackers used booking context embedded in SMS, email, WhatsApp, and in-app messages to drive fraudulent payment flows. Booking platforms reported exposure of reservation-linked personal and contact data during related incidents.
FIFA-themed fraud activity escalated as attackers registered typosquatting domains impersonating official World Cup services. The FBI listed domains including fifa[.]cab, fifa[.]help, and fifa-2026[.]xyz used for harvesting financial and identity data. Campaigns focused on fake ticketing and hospitality payment portals tied to event interest.
Major data breach activity continued with Carnival Corporation confirming unauthorized access impacting nearly six million individuals. Attackers used social engineering against an employee account to access names, addresses, contact details, and identity-related information. The breach followed prior incidents involving phishing and ransomware activity in previous years.
Software supply-chain compromise activity included a malicious Sicoob.Sdk NuGet package distributing credential and certificate exfiltration functionality. The package transmitted PFX credentials and banking certificates to a hardcoded Sentry endpoint during client operations. The payload enabled potential impersonation of financial API services linked to Sicoob infrastructure.
Ransomware operations included the emergence of Gentlemen ransomware, a Go-based encryptor with self-propagation capabilities across Windows environments. The malware used Curve25519 encryption and XChaCha20 per-file encryption while spreading through PsExec, WMI, and scheduled tasks. It disabled security tooling and deleted recovery artefacts during execution.
State-linked mobile malware activity included Sapphire Sleet targeting macOS systems using fake Zoom SDK updates. The intrusion chain used AppleScript execution and credential harvesting prompts combined with LaunchDaemons persistence mechanisms. Attacks focused on financial and cryptocurrency-related targets.
Highlights of the Day
ShinyHunters Breach Exposes Six Million Carnival Records
Carnival confirmed a breach linked to ShinyHunters involving an April 14 social engineering attack on an employee affecting six million individuals. Carnival filing with the Maine attorney general’s recorded just under six million, with exposed names, addresses, emails, phone numbers, birth dates and state ID numbers.
North Korean group targets macOS financial sector campaign
Sapphire Sleet, a North Korean group tracked as BlueNoroff/UNC1069, ran a macOS intrusion campaign targeting financial and cryptocurrency organisations using a fake Zoom SDK update. Initial access used social engineering delivering an AppleScript executed through Script Editor, osascript and curl, with a fake macOS password prompt used for credential harvesting and Finder abused for TCC.db manipulation under Full Disk Access permissions, enabling persistence via a LaunchDaemons service and data theft.
Microsoft details self-propagating Gentlemen ransomware Go variant
Microsoft documented The Gentlemen ransomware operated by Storm-2697 as a Go-based RaaS encryptor targeting Windows systems with self-propagating capabilities and double extortion. It uses Curve25519 and XChaCha20 per-file encryption and a self-propagation module that abuses multiple Windows lateral movement techniques for network-wide compromise across enterprise environments. It disables Microsoft Defender, deletes shadow copies and event logs, and terminates security, backup and database services while propagating via PsExec, WMI and scheduled tasks.
Malicious NuGet package steals Sicoob banking certificates
Sicoob.Sdk NuGet package versions 2.0.0–2.0.4 impersonated a Brazilian banking SDK and exfiltrated client IDs, PFX passwords, and base64-encoded certificate archives via a hardcoded Sentry endpoint. The library disguised as a .NET 8 Sicoob SDK reads local PFX files during client construction and transmits certificates and credentials through Sentry telemetry. Socket analysis linked the payload to a fake Sicoob-Cooperativa GitHub organisation and confirmed NuGet blocking after abuse reports, with stolen certificates enabling Sicoob API impersonation.
FBI warns of FIFA website spoofing ahead 2026 World Cup
The FBI issued a PSA warning that cyber actors are spoofing FIFA websites ahead of the 2026 World Cup using typosquatting. Spoofed sites mimic fifa.com with minor spelling changes and alternative domains, harvesting names, addresses, banking details, and selling fake tickets and hospitality products. The FBI listed multiple example domains including fifa[.]cab, fifa[.]pink, fifa[.]help, fifa-2026[.]xyz and related variants identified for fraud monitoring and reporting via IC3.
Reservation Hijack scams exploit booking data across 50 countries
Reservation Hijack scams targeting travel bookings used reservation-specific phishing pages and spoofed communications, with Booking.com notifying customers that unauthorised access to reservation-linked information exposed names, contact details and booking data. Identified more than 350 compromised accommodations across 50 countries spanning hotels, apartments, hostels, resorts and guesthouses where attackers used intercepted reservation context across SMS, email, WhatsApp and in-app messaging to direct victims to fraudulent payment and verification pages built on reusable phishing infrastructure.
Daily Coverage