Threat IntelHIGH

RingH23 Toolkit Threatens Millions with CDN Compromise

CSCyber Security NewsMar 5, 2026
FunnullRingH23CDNMacCMS
🎯

Basically, a hacker group is using a new tool to redirect users to bad websites.

Quick Summary

A hacker group is using a new tool called RingH23 to compromise CDN infrastructure and redirect users to illegal sites. This affects millions of internet users and poses serious online safety risks. Stay updated and protect yourself against these threats.

What Happened

A new cyber threat has emerged, and it’s called RingH23. This toolkit? is being used by a notorious group known as Funnull, which has previously faced sanctions from the U.S. Treasury. Their latest campaign targets content delivery networks (CDN?s) and the MacCMS? content management system, allowing them to silently redirect millions of unsuspecting users to illegal websites.

This isn't just a minor issue; it's a significant escalation in Funnull’s tactics. By compromising CDN? nodes, they can infiltrate the infrastructure that many websites rely on. This means that even reputable sites could unknowingly lead users to harmful content. The scale of this operation is alarming, as it threatens the online safety of countless individuals.

Why Should You Care

You might think this doesn't affect you, but it does. If you visit a website that uses a compromised CDN?, you could be redirected to a malicious site without even realizing it. Imagine walking into a store only to find out it’s a front for illegal activities. That’s what’s happening online right now.

Every time you click on a link or visit a site, you trust that it’s safe. With tools like RingH23 in play, that trust is being exploited. Your online safety is at risk, and it’s crucial to stay informed about these threats.

What's Being Done

In response to this alarming situation, cybersecurity experts are closely monitoring the activities of Funnull and the RingH23 toolkit?. Here are some immediate actions you can take to protect yourself:

  • Keep your software and systems updated to the latest versions.
  • Use reputable security tools to scan for potential threats.
  • Be cautious about the links you click, especially from unfamiliar sources.

Experts are watching for any new developments and advise users to remain vigilant. The situation is evolving, and staying informed is your best defense against these cybercriminal?s.

💡 Tap dotted terms for explanations

🔒 Pro insight: Funnull's use of RingH23 indicates a shift towards more sophisticated attack vectors targeting critical web infrastructure.

Original article from

Cyber Security News · Tushar Subhra Dutta

Read Full Article

Related Pings

HIGHThreat Intel

Alignment: The Key to Cybersecurity Success

Organizations are prioritizing alignment in cybersecurity to enhance their defenses. This affects everyone, as misalignment can leave your data exposed. Companies are now investing in training and collaboration to strengthen their security posture. Stay informed about how these changes impact your safety online.

Anthropic Research·Today, 3:38 AM
HIGHThreat Intel

FBI Probes Suspicious Cyber Activity on Surveillance Systems

The FBI is looking into suspicious cyber activity affecting sensitive surveillance systems. This could impact privacy and data security. Stay informed and review your own security practices.

SecurityWeek·Today, 1:01 AM
MEDIUMThreat Intel

AI-Powered Cyber Defense: Trump's New Strategy Unveiled

The Trump administration has announced a new cybersecurity strategy focusing on AI for defense. While promising, it lacks crucial details. This could affect your online security, so stay informed about developments.

Cybersecurity Dive·Yesterday, 10:36 PM
HIGHThreat Intel

Iran's MuddyWater Breaches Multiple U.S. Organizations

Iran's MuddyWater hacking group has breached multiple U.S. organizations, raising significant security alarms. These attacks could compromise sensitive information and disrupt essential services. The FBI is investigating, and Cisco has issued critical patches to address vulnerabilities.

CyberWire Daily·Yesterday, 9:30 PM
HIGHThreat Intel

MuddyWater APT Hits U.S. Organizations with Dindoor Malware

MuddyWater, an Iranian hacker group, is targeting U.S. organizations with new Dindoor malware. Banks, airports, and nonprofits are at risk of data breaches and disruptions. Cybersecurity teams are responding with updates and monitoring measures to protect sensitive information.

Security Affairs·Yesterday, 8:05 PM
HIGHThreat Intel

North Korean Threat Groups Exploit AI for Fake Worker Schemes

North Korean hackers are using AI to create fake job applicants. This tactic poses serious risks to companies and their sensitive data. Microsoft warns organizations to enhance their recruitment processes to combat this growing threat.

CyberScoop·Yesterday, 7:16 PM