Log4j Alert Calmed; Minimus Shuts; US Sanctions Iranian Hackers
Developers called a Log4j 2 RCE report a “known security non‑finding.” Minimus is winding down after a $51M 2025 raise and was acquired by Echo; the U.S. Treasury sanctioned Iranian cyber actors.
Apache Log4j maintainers acknowledged a potential remote code execution issue in Log4j 2 but described it as a “known security non‑finding.” The maintainers confirmed exploitation requires specific conditions and advised defenders to prioritize other, higher‑risk problems while recalling the damage caused by the earlier Log4Shell flaw.
Minimus, a provider of hardened container images that raised $51 million in 2025, announced it was winding down operations, citing the business and investment climate as reasons for the closure. The announcement came days after the company’s appearance at a security conference. Echo acquired Minimus and its technology shortly after the winding‑down notice; financial terms were not disclosed. Customers and partners await details on continuity of support and the status of active deployments that relied on Minimus images.
The U.S. Treasury designated a set of Iranian cyber actors it linked to the Ministry of Intelligence and Security (MOIS). Named individuals include Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda’i. The Treasury accused the designated actors of compromising critical infrastructure and carrying out financially motivated cyber theft, and noted overlap between some designated individuals and a group of 17 Iranians charged by the FBI. The Treasury identified victims outside Iran.
Credential exposure research identified active risks to cloud accounts and developer secrets. A review of 10,616 exposed AWS keys from 2022 to 2026 found more than 700 active corporate AWS keys that could grant full account control. A separate scan of 3.5 million active hosts uncovered 28,000 exposed Git repositories and active secrets including over 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens and 17 GitHub personal access tokens.
Mobile banking malware activity expanded across multiple countries. Analysis of mobile threats showed 30 malware families actively targeting more than 800 banking and fintech apps across 44 countries in Europe, the Middle East and Africa. The analysis found attackers increasingly use artificial intelligence to automate localized lures, exploit scripting and produce more convincing phishing pages and overlays.
Several data breaches and ransomware incidents were reported. Paylogix reported that attackers stole files from its network over several days in November, exposing Social Security numbers, financial and insurance information, medical records, passport numbers and taxpayer IDs. At least 67,789 people in South Carolina, New Hampshire and Vermont were reported affected; the Akira ransomware group claimed responsibility.
Manchester Airports Group reported that hackers accessed personal data for about 8.7 million customers, including email addresses, phone numbers, vehicle registration details and postcodes. Manchester Airports Group declined to pay a ransom and stated airport operations and passenger safety were not affected.
U.S. Bancorp responded to ransomware claims tied to its name by attributing the alleged theft to a potential incident at a fourth‑party provider and noting there is no evidence the bank’s systems, networks or data repositories were compromised. The LockBit group threatened to publish files it said it held.
An analysis of data tied to an alleged Carhartt breach found that a large share of the records were synthetic TPC‑DS benchmark data mixed with genuine customer information, indicating the volume of real exposed emails was substantially overstated.
Leaked training materials from Bauman University revealed a program that trained roughly 250 students in offensive and defensive cyber techniques, malware analysis and intelligence work. Graduates of the program were linked to units associated with Russian threat groups.
The week’s items include a clarified Log4j vulnerability, a security vendor winding down and being acquired, U.S. Treasury sanctions on Iran‑linked cyber actors, multiple credential exposures and several significant data breaches and malware campaigns.








