Breach Roundup: Def Con Dolt Suspected in Delta Wi-Fi Hack
Data Breach TodayArchived Aug 14, 2026✓ Full text saved
Also, LiteLLM Attack Exposed 430,000 Pipelines, Ukrainian IT Workers Targeted This week: An evil twin attack on a Delta flight, the LiteLLM attack exposed 430,000 pipelines, Russian hackers targeted Ukrainian IT workers with fake job interviews, a Cisco warning over ClamAV flaws, ransomware extortionists hacked a healthcare sector victim's Facebook and ClickFix attacks.
Full text archived locally
✦ AI Summary· Claude Sonnet
Cybercrime , Fraud Management & Cybercrime , Incident & Breach Response Breach Roundup: Def Con Dolt Suspected in Delta Wi-Fi Hack Also, LiteLLM Attack Exposed 430,000 Pipelines, Ukrainian IT Workers Targeted Anviksha More ( AnvikshaMore ) • August 13, 2026 Credit Eligible Get Permission Every week, ISMG rounds up cybersecurity incidents and breaches around the world. This week: A Delta Air Lines passenger launched an evil twin attack, LiteLLM attack exposed 430,000 pipelines, Russian nation-state hackers targeted Ukrainian IT workers with fake job interviews, a Cisco warning over ClamAV flaws, ransomware extortionists hacked a healthcare sector victim's Facebook and ClickFix attacks. See Also: Scattered Spider Exposed: Critical Takeaways for Cyber Defenders Delta Crew Distraught Over Suspected Def Con Wi-Fi Dolt A passenger on a Delta Air Lines flight to Atlanta is suspected of jamming the on-board Wi-Fi and mounting an evil twin attack in an apparent bid to capture passenger online credentials. The Monday flight of Delta flight 591 occurred one day after the Def Con security conference in Las Vegas wrapped up. Flight watchers The spotted a crew message transmitted over the ACARS system stating "WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." The crew then said they detected a scam Wi-Fi signal being broadcast as Delta WiFi Fast. "WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX," the crew said. Social media posts on X, Facebook and Reddit variously claimed the passenger conducted a deauthentication attack, forcing users off the legitimate onboard network before deploying a fake Wi-Fi landing page. Some suggested a device such as a Wi-Fi Pineapple may have been involved. On user said attempting to login to the Delta WiFi Fast signal triggered a phishing landing page "designed to harvest passengers’ personal credentials." Claims that federal agents were waiting at the gate were disputed by passengers. The Federal Aviation Administration and the FBI have said they are looking into the incident. Delta confirmed to the Register that an unauthorized Wi-Fi network was briefly broadcast onboard. The airline said cabin crew disabled the aircraft's Wi-Fi for about 30 minutes during the incident, which may have contributed to reports of a deauthentication attack. If investigators determine that the passenger intentionally interfered with authorized Wi-Fi communications, the consequences could be serious. The Federal Communications Commission says intentional Wi-Fi blocking can violate 333 of the Communications Act, with willful violations potentially carrying up to one year in prison and a $10,000 fine . Repeat offenses can carry longer sentences. Knocking off a legitimate Wi-Fi signal and replacing it with a signal controlled by an attacker is a well-honed attack technique the subject of many warnings over the years (see: Breach Roundup: Australian IT Worker Sentenced for 'Evil Twin' Wi-Fi Crime ). LiteLLM Attack Exposed 430,000 Pipelines More than 2,500 organizations and 434,000 continuous integration, continuous deployment pipelines were potentially exposed in the LiteLLM supply chain attack earlier this year, reported CloudSEK. The incident stemmed from the compromise of Aqua Security's Trivy open-source vulnerability scanner by TeamPCP. The threat actor did not directly target LiteLLM. Instead, its CI/CD pipeline automatically installed a compromised Trivy version, enabling attackers to compromise the build process. Malicious LiteLLM versions 1.82.7 and 1.82.8 were then published to PyPI. The packages contained code that executed whenever Python ran, potentially exposing credentials and other information accessible to the library. Although the malicious versions remained available for only about 40 minutes, CloudSEK said automated build systems allowed the exposure to spread rapidly. Security researcher Kevin Beaumont suggested the impact may persist despite organizations rotating credentials. "These creds date from about March," Beaumont said in a Mastodon post. After one affected organization said it had rotated all credentials, Beaumont said he tested them under the company's responsible disclosure policy. "Almost everyone worked," he wrote, adding that he had submitted a report to "one of the biggest US techcos." Potentially exposed data included package-publishing credentials, cloud and AI-provider keys, SSH keys, tokens and environment variables. CloudSEK stressed that its figures represent reconstructed exposure and do not prove every organization was compromised. Russian Hackers Target Ukrainian IT Workers With Fake Jobs Russian intelligence agency hackers are targeting Ukrainian IT professionals with fake job offers designed to trick them into installing malware, found Ukraine's Computer Emergency Response Team. CERT-UA attributed the attacks, ongoing since May, to a threat actor popularly known as Sandworm or Voodoo Bear, but which is officially Unit 74455 of the Russian Main Intelligence Directorate or GRU, a spy agency within the Russian military. Attackers contact system administrators and IT specialists through job-search platforms, posing as recruiters for legitimate companies. Conversations are moved to Telegram, followed by a purported interview over Zoom. Candidates are then sent technical-assessment instructions containing WireGuard VPN configuration files. When the connection fails, victims are directed to download a supposedly legitimate corporate VPN client called SopraVPN. CERT-UA found that the malicious Windows and Linux VPN clients were modified versions of WireGuard. The software can decrypt attacker-supplied data and execute arbitrary PowerShell commands on Windows hosts. It also creates scheduled tasks to download additional payloads, while the Linux version uses cURL to retrieve malware from attacker-controlled infrastructure. Fake job recruitment has been a mainstay of North Korean social engineering technique for years, a method also lately embraced by Iran - and now Russia, which has built closer ties to Pyongyang by enlisting the authoritarian regime as an ally in its invasion of European neighbor Ukraine (see: North Korean IT Worker Scams Fueling Ukrainian Invasion ). Cisco Warns of ClamAV DoS Flaws Cisco warned of two high-severity vulnerabilities in ClamAV, open source antivirus software developed by its Talos threat intelligence division. Tracked as CVE-2026-20337 and CVE-2026-20338 , the flaws affect ClamAV's ZIP archive parser and stem from improper boundary checks and memory handling. Attackers can exploit them by submitting specially crafted ZIP files for scanning. They could enable remote, unauthenticated attackers to crash the antivirus engine and cause denial-of-service conditions. Cisco's Product Security Incident Response Team said proof-of-concept code is publicly available but found no evidence of exploitation in the wild. The vulnerabilities affect ClamAV versions 1.5.0 through 1.5.3 and were patched in version 1.5.4, released Aug. 7. Cisco said the flaws pose a high security impact only on Windows because ClamAV runs with privileged security context on that platform. AnMed Facebook Account Hacked AnMed, a non-profit health system that serves upstate South Carolina and northeast Georgia, said this week it is getting closer to restoring various IT systems - including its electronic health records - taken offline in the aftermath of a ransomware attack discovered on July 26 (see: Malware Attack Forces AnMed to Close Care Facilities ). Ransomware gang The Gentlemen reportedly hacked into AnMed's Facebook account, posting a series of threats on Tuesday morning. The gang claimed to have 6 terabytes of stolen AnMed corporate data and patient information - including records pertaining to mental health, sexual assaults, reproductive care, genetic testing and cancer. AnMed acknowledged Tuesday afternoon that its social media accounts were hacked and defaced with unauthorized posts. "AnMed and its cybersecurity specialists are investigating the matter," it said. ClickFix Campaign Abuses Deno to Deliver Infostealer Threat actors used the Deno JavaScript runtime to deliver an information-stealing malware in a June campaign that compromised more than 500 WordPress sites, found Sophos. The campaign used ClickFix-themed social engineering lures disguised as Cloudflare verification prompts. Visitors to compromised websites were instructed to copy and execute a PowerShell command through Windows Terminal. The command triggered an MSI-based infection chain that installed Deno using Windows' winget utility. The legitimate deno.exe was then used to retrieve and execute JavaScript hosted on attacker-controlled infrastructure, allowing the attackers to deliver additional payloads without relying on traditional malware loaders. Sophos researchers said Deno also enabled system reconnaissance, additional PowerShell execution and persistence through Registry Run keys. The attackers ultimately used the runtime to deliver a Python-based infostealer capable of collecting system information, browser and extension data, cryptocurrency wallet information and keystrokes. The campaign was observed June 3 and June 4, with Sophos later identifying more than 500 compromised WordPress sites hosting similar malicious JavaScript. Researchers said the scale suggested the attackers were using automated website compromises or injection techniques to distribute the ClickFix lure. Sophos noted that Deno's trusted, code-signed distributions, introduced in a 2025 release, could make the legitimate runtime less likely to trigger security controls. Its ability to retrieve remote code and execute it with broad permissions also makes it attractive for malware delivery and persistence. Other Stories From Last Week Chinese Hackers Run Dual Operations: Espionage and Crypto Fraud Why a New National Water Cyber Program May Miss the Real Gap Rush to Build Data Centers Leaves OT Security Behind Zoom Flaws Facilitate Zero-Click Remote Code Execution Mistral Expands Sovereign AI Push With European Compute With reporting by ISMG's Marianne Kolbasuk McGee in the Boston exurbs.