BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Threat Roundup: AI-Generated Malware, Corporate Breaches, and Android Lock Screen Bypass

Threat Roundup: AI-Generated Malware, Corporate Breaches, and Android Lock Screen Bypass

March 13, 2026Malware & Threats4 min readhigh

Originally reported by BleepingComputer, Graham Cluley, Cisco Talos, Checkpoint Research, Malwarebytes Labs

#data-breach#ransomware#malware#android#signal#veeam#rce
Share

TL;DR

This week saw significant corporate data breaches at Starbucks and Telus Digital, alongside the emergence of AI-generated Slopoly malware used in ransomware attacks. Critical vulnerabilities in Veeam backup software and an Android lock screen bypass vulnerability highlight ongoing infrastructure security challenges.

Why high?

Multiple critical RCE vulnerabilities in Veeam backup software combined with large-scale corporate breaches affecting hundreds of thousands of users warrants high severity classification.

Starbucks Employee Data Breach

Starbucks disclosed a data breach affecting hundreds of employees after threat actors gained unauthorized access to Starbucks Partner Central accounts. The incident compromised employee personal information stored within the partner portal system. The coffee giant has initiated security measures and is working with affected employees to secure their accounts.

Loblaw Customer Data Incident

Canadian retail giant Loblaw notified customers of a security incident that prompted the company to automatically log out all users from their digital accounts. As a precautionary measure, customers must re-authenticate to access Loblaw's digital services. The company has not disclosed the full scope of potentially compromised data.

England Hockey Targeted by AiLock Ransomware

England Hockey confirmed it is investigating a potential data breach after the AiLock ransomware group listed the organization as a victim on its leak site. The governing body for field hockey in England has not yet confirmed the extent of any data compromise or operational impact.

AI-Generated Slopoly Malware in Interlock Campaign

Researchers identified a new malware strain dubbed Slopoly, believed to be generated using AI tools, deployed in an Interlock ransomware attack. The malware allowed threat actors to maintain persistence on a compromised server for over a week, facilitating data exfiltration before encryption. This represents an evolution in AI-assisted malware development.

Critical Veeam RCE Vulnerabilities Patched

Veeam Software addressed multiple critical vulnerabilities in its Backup & Replication solution, including four remote code execution flaws. The vulnerabilities could allow attackers to compromise backup infrastructure, potentially disrupting recovery operations. Organizations using Veeam products should prioritize applying the available patches.

SocksEscort Proxy Network Disrupted

U.S. and European law enforcement agencies disrupted the SocksEscort cybercrime proxy network, which leveraged compromised Linux edge devices infected with AVRecon malware. The network provided proxy services to cybercriminals for various malicious activities. The operation demonstrates continued international cooperation in dismantling cybercrime infrastructure.

Google Vulnerability Rewards Hit $17.1 Million

Google's Vulnerability Reward Program paid out over $17 million to 747 security researchers in 2025, highlighting the continued value of coordinated vulnerability disclosure programs. The substantial payouts reflect both the volume and severity of security issues identified in Google's products and services.

Telus Digital Confirms Massive Data Theft

Telus Digital confirmed a security incident after threat actors claimed to have stolen nearly 1 petabyte of data during a multi-month breach. The Canadian business process outsourcing company is investigating the scope and impact of the compromise, which could affect numerous client organizations.

Travel Rewards Become Underground Currency

Flare research revealed how cybercriminals monetize stolen airline miles and loyalty points, converting them into discounted travel bookings for resale. The underground market treats loyalty program credentials as tradable commodities, highlighting the broader value of seemingly non-financial account credentials.

Signal Account Takeovers Target Officials

Security researchers documented account takeover attacks against Signal users, particularly targeting government officials and journalists. The attacks exploit social engineering tactics rather than platform vulnerabilities, emphasizing the importance of user awareness in maintaining secure communications.

Iranian Handala Hack Group Analysis

Check Point Research published detailed analysis of Handala Hack (Void Manticore), an Iranian threat actor conducting destructive wiping attacks combined with hack-and-leak operations. The group maintains multiple online personas, with Homeland Justice being the most prominent since mid-2022.

Fake Temu Crypto Airdrop Delivers Malware

Malwarebytes Labs identified a campaign using fake $TEMU cryptocurrency airdrops to distribute malware via ClickFix social engineering techniques. Victims are tricked into executing malicious code that installs a remote access backdoor, demonstrating continued evolution in cryptocurrency-themed lures.

Android Lock Screen Bypass Vulnerability

Researchers demonstrated an Android vulnerability allowing lock screen bypass in under 60 seconds. The attack enables extraction of encryption keys, PIN recovery, and access to sensitive device data. The technique affects certain Android configurations and highlights mobile security implementation challenges.

Cisco Talos on Security Allyship

Cisco Talos published commentary on allyship in cybersecurity, emphasizing awareness as the first step in addressing industry challenges. The piece discusses the importance of recognizing and addressing systemic issues within the security community.

Sources

  • https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/
  • https://www.bleepingcomputer.com/news/security/canadian-retail-giant-loblaw-notifies-customers-of-data-breach/
  • https://www.bleepingcomputer.com/news/security/england-hockey-investigating-ransomware-data-breach/
  • https://www.bleepingcomputer.com/news/security/ai-generated-slopoly-malware-used-in-interlock-ransomware-attack/
  • https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/
  • https://www.bleepingcomputer.com/news/security/us-disrupts-socksescort-proxy-network-powered-by-linux-malware/
  • https://www.bleepingcomputer.com/news/google/google-paid-171-million-for-vulnerability-reports-in-2025/
  • https://www.bleepingcomputer.com/news/security/telus-digital-confirms-breach-after-hacker-claims-1-petabyte-data-theft/
  • https://www.bleepingcomputer.com/news/security/going-the-extra-mile-travel-rewards-turn-into-underground-currency/
  • https://www.bitdefender.com/en-us/blog/hotforsecurity/signal-account-safe-unless-fall-for-this-trick
  • https://blog.talosintelligence.com/this-ones-for-you-mom/
  • https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/
  • https://www.malwarebytes.com/blog/threat-intel/2026/03/fake-temu-coin-airdrop-uses-clickfix-trick-to-install-stealthy-malware
  • https://www.malwarebytes.com/blog/news/2026/03/this-android-vulnerability-can-break-your-lock-screen-in-under-60-seconds

Originally reported by BleepingComputer, Graham Cluley, Cisco Talos, Checkpoint Research, Malwarebytes Labs

Tags

#data-breach#ransomware#malware#android#signal#veeam#rce

Tracked Companies

🇺🇸Google

Related Intelligence

  • Threat Intelligence Digest: Chinese APT Campaign, Critical Router RCE, and Agent Tesla Resurgence

    highFeb 26, 2026
  • Malware Roundup: 651 Cybercriminals Arrested, New Android Banking Trojan, Critical CCTV Flaw

    criticalFeb 19, 2026
  • Ransomware Devastates Oceania Healthcare While New Threats Target Critical Infrastructure

    highMar 12, 2026

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Apple Patches iOS 15.8.7 for Legacy iPhone 6S Against Coruna Exploit

Next Article

Privacy-Surveillance Roundup: Big Tech Brain Drain, NATO Device Certification, FBI Warrant Reform, and Iranian Hacktivism →