Log4j RCE Scare Turns Out to Be a Non-Finding
A new report claiming a remote-code-execution issue in Apache Log4j 2 caused a brief wave of panic this week — understandably, given Log4j's history with the catastrophic Log4Shell vulnerability in 2021. The Log4j maintainers pushed back quickly, characterizing the new report as a "known security non-finding": RCE is technically reachable only under narrow, unusual configuration conditions that don't reflect how the library is deployed in practice. No CVE was assigned. The episode is a useful reminder to verify exploitability conditions before escalating — and a sign of how much residual anxiety Log4Shell still generates industry-wide.
U.S. Bancorp Disputes LockBit Breach Claim
The LockBit ransomware operation claimed to have breached U.S. Bank and threatened to publish stolen data. U.S. Bancorp says the incident it's aware of actually originates with a fourth-party provider outside its own environment, and that it has found no evidence its own systems, networks, or data repositories were compromised. The bank previously addressed a related third-party claim earlier this month — see our prior coverage for background on that incident.
Container-Security Startup Minimus Shuts Down
Minimus, a hardened-container-image security vendor that raised $51 million in 2025 and had exhibited at Black Hat USA just weeks earlier, is winding down operations. Its technology and team have been acquired by Echo. The shutdown is a notable data point in a crowded supply-chain-security funding market where not every well-capitalized entrant survives to its next round.
Hundreds of Live Cloud Credentials Found Sitting in Public Repos
Two separate research efforts this week quantified just how much exposed credential sprawl remains a persistent problem. Truffle Security scanned 10,616 exposed AWS keys collected between 2022 and 2026 and found more than 700 still live, with full account-takeover potential. Separately, Intruder scanned 3.5 million active hosts and found roughly 28,000 exposed Git repositories leaking over 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram bot tokens, and 17 GitHub personal access tokens. Neither finding is new in kind, but the scale underscores that secret-scanning hygiene remains an unsolved problem for a meaningful share of the internet's exposed Git infrastructure.
Zimperium Tracks 30 Malware Families Targeting 800+ Banking Apps
Zimperium researchers catalogued 30 active mobile malware families targeting more than 800 banking and fintech applications across 44 countries in the EMEA region. The report flags a growing trend of attackers weaving AI into the malware development and targeting chain — automating the process of adapting overlay attacks and phishing lures to new banking app targets faster than defenders can catalogue them.
Carhartt Breach Data Was Only Half Real
Security researcher Troy Hunt's analysis of the ShinyHunters-attributed Carhartt breach dataset found that roughly half of the ~24.8 million email addresses in the leak were synthetic — mixed in from TPC-DS benchmark test data rather than genuine customer records. The finding doesn't clear Carhartt of a real breach, but it does mean the actual scope of exposed customer data was significantly overstated by the raw record count, a pattern worth watching for in other high-volume breach claims.
Manchester Airports Group Breach Affected 8.7 Million Customers
Further detail emerged this week on the Manchester Airports Group (MAG) cyberattack, which we covered previously: the breach affected approximately 8.7 million customers, exposing emails, phone numbers, vehicle registrations, and postcodes. Attackers demanded a ransom, which MAG refused to pay. Airport operations, passenger safety, and aviation security systems were not affected.
U.S. Sanctions Iranian MOIS-Linked Hackers
The U.S. Treasury sanctioned three individuals — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i — linked to Iran's Ministry of Intelligence and Security (MOIS) for critical-infrastructure compromise and financially motivated cyber theft. The designations cover four of the 17 Iranian hackers previously charged by the FBI, adding financial sanctions on top of existing criminal charges.