'BusySnake' Infostealer Slithers into Critical Infrastructure Networks

2026-07-07T02:51:58Z92f0f638d7b920da8d51b4e7432cbfbf930d43784c8148a371d0e5a641dc5498
AI supply-chainBusySnakeCVE-2026-48558CitrixBleedDjinnFortiBleedFortinetJadePufferLLM-driven ransomwareLangflowNetScalerNextcloud zero-daySimpleHelpagentjackingcredential-theftexposed-AI-endpointsinfostealerphantom-squattingphishing

What happened

Multiple active, high-impact campaigns and emerging AI-driven threats were reported: a new 'BusySnake' infostealer (attributed to 'Armored Likho') has compromised government and electrical power organizations across Russia, Brazil and Kazakhstan; the 'Djinn' stealer is being delivered via a critical SimpleHelp authentication-bypass (CVE-2026-48558) to harvest cloud/AI credentials; Citrix NetScaler memory-disclosure ("CitrixBleed") PoCs are being weaponized; an LLM-driven ransomware campaign ('JadePuffer') exploited a Langflow flaw to steal data and encrypt systems; FortiBleed actors that have침

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
92f0f638d7b920da8d51b4e7432cbfbf930d43784c8148a371d0e5a641dc5498
Enrichment time
2026-07-07T02:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.