Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

2026-08-23T19:23:59Ze145b474f1182ceebc24a611e527c8d5f08c26dc5c1e00efd63efd64b5696f3f
AI-securityGeminiGrandoreiroGrokManicMicrosoft-Entra-IDNorth-Korean-threat-actorRustToxicPanda-2.0TrueConf-Server-CVE-exploitation-mitigationV8-sandbox-escapearrayrefbanking-trojancredential-thefthost-compromiseiAuthFlow-V2isolated-vmmalwarepasskeyspersistencephishingpoisoned-packageprompt-injectionremote-code-executionsoftware-supply-chain

What happened

SecurityWeek roundup covering banking trojans, AI safety bypasses, phishing persistence via passkeys, a critical isolated-vm host RCE, a Rust package supply-chain attack attributed to North Korean hackers, actively exploited Microsoft Entra ID and TrueConf vulnerabilities, and related cybersecurity developments. The highest-priority items are the actively exploited vulnerabilities and host escape risk, while the phishing toolkit and poisoned dependency present significant account and software supply-chain threats.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
e145b474f1182ceebc24a611e527c8d5f08c26dc5c1e00efd63efd64b5696f3f
Enrichment time
2026-08-23T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.