212 New Venezuela Earthquake Domains Prompt Donation Scam Warnings
2026-06-30T08:51:40Z•9bb5af02468937ea3758bd4222d2a616b192a9dd0a62b414ba04a1e1e1bd5f4f
Aubrey CottleBluekitCrowdStrikeKandjiMistic RATSASTWoodgnatbackdoorbrowser-in-the-middlecyber-rangecybercrimedonation-scamendpoint-bypasshacktivismmacOS XPCpatchphishingphishing-as-a-serviceransomware-access-brokeringtyposquat-domainsvendor-closuresvulnerability
What happened
Multiple security items: researchers identified 212 newly-registered domains exploiting Venezuela’s earthquake to run donation scams and warn donors to verify relief sites. A new phishing-as-a-service (Bluekit) uses browser-in-the-middle techniques to steal accounts and evade detection. Woodgnat threat actors deploy the stealthy Mistic RAT as a brokered backdoor to sell network access to ransomware gangs. A macOS XPC vulnerability allowed standard users to disable CrowdStrike and Kandji endpoint agents (vendors issued patches after disclosure). Other industry notes include Cyberbit closing its
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 9bb5af02468937ea3758bd4222d2a616b192a9dd0a62b414ba04a1e1e1bd5f4f
- Enrichment time
- 2026-06-30T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.