MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data

2026-07-27T20:51:47Z44361fa0a6bb7c9bd5d9f6631a72beb6c5328bd532a7b31bf767a9a91f929b65
GitLabICSIran-linked-threat-actorsLockBit5MedusaHVNCMicrosoft-365OT-securityOj-parserQilinRATWi-Fi-compromisebrowser-hijackingcredential-theftcritical-infrastructuredata-breachdata-theftenergy-sectorevasionhealth-datamalwarephishingprivacyransomwareremote-code-executionwater-sector

What happened

Security Affairs feed covering active threats and incidents including MedusaHVNC browser hijacking, a critical GitLab authenticated remote-code-execution chain involving Oj parser flaws, ransomware activity by LockBit5 and Qilin, hotel Wi-Fi credential theft, Iran-linked targeting of exposed water and energy control systems, and major data breaches affecting DentaQuest and Origin Energy customers. The feed also includes privacy concerns for smart wearables and a malware-news roundup.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
44361fa0a6bb7c9bd5d9f6631a72beb6c5328bd532a7b31bf767a9a91f929b65
Enrichment time
2026-07-27T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data · Baitaphish