Blogs

In Other News: VPN Supply Chain Attack, PayPal $2M Settlement, RAT Builder Hacks Script Kiddies

Cybersecurity news roundup covering supply-chain attacks, payment security and malware

Summary: This security roundup highlights three unrelated incidents with a shared lesson: trusted software, routine payment workflows and even tools used by inexperienced attackers can become delivery paths for compromise.

VPN supply-chain compromise

SecurityWeek reported that ESET researchers linked the PlushDaemon threat group to a supply-chain attack against a South Korean VPN provider. Attackers replaced a legitimate installer with a trojanized package, allowing selected users to receive malicious code through a channel they expected to trust. The incident reinforces the need to verify software provenance and monitor newly installed applications for unusual outbound activity.

PayPal’s $2 million New York settlement

New York’s Department of Financial Services announced a $2 million penalty against PayPal over cybersecurity control failures connected with a 2022 exposure of sensitive customer information. The regulator’s consent order points to weaknesses in change management, access controls and testing. For organizations, the practical message is that security review must be part of every production change—not an afterthought.

Trojanized XWorm builder

A modified builder for the XWorm remote-access trojan was itself used to infect people attempting to create malware. CloudSEK estimated that the campaign compromised thousands of devices. Although the victims were “script kiddies,” the technique is a conventional software supply-chain trap: a seemingly useful tool delivers an additional hidden payload.

Practical takeaway

  • Download software only from validated channels and verify signatures or hashes where available.
  • Test security impact before production changes and restrict access to sensitive data.
  • Alert on unexpected processes and network connections immediately after software installation.

Original sources: SecurityWeek — weekly security roundup; New York Department of Financial Services — PayPal consent order (PDF)

Independently summarized and reviewed by CNB Telecom. Last reviewed: September 4, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *