Search/nextcloud
Vendor

nextcloud

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
nextcloud mail
Connections
59 relationships
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}"). "The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences," according to an advisory published by Windmill in March 2026. "The primary sensitive value exposed by this vulnerability is the SUPERADMIN_SECRET environment variable, readable via /proc/1/environ. When set, this secret can be used as a Bearer token to authenticate as a superadmin and execute arbitrary code through the job preview API." However, it's worth noting that SUPERADMIN_SECRET is not set by default, and for standalone Windmill instances without SUPERADMIN_SECRET configured, the impact of the vulnerability is limited to arbitrary file read. The issue has since been addressed in Windmill 1.603.3, released in January 2026, by adding sanitization checks to the filename parameter to prevent directory traversal. According to VulnCheck, whose security researcher Valentin Lobstein is credited with discovering and reporting the flaw, exploitation efforts have been directed against Windmill's "get_log_file" endpoint to extract sensitive information from the "/etc/passwd" file. "We've observed exploits aimed at both direct Windmill endpoints and the Nextcloud proxy path," Caitlin Condon, vice president of security research at VulnCheck, said in a post on LinkedIn. The cybersecurity company said it identified about 170 vulnerable systems exposed across 24 countries. The disclosure comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, including two WordPress bugs tracked as wp2shell (CVE-2026-60137 and CVE-2026-63030), along with a stack-based buffer overflow in DD-WRT (CVE-2021-27137) and an unauthenticated remote code execution issue in Langflow (CVE-2026-0770). "wp2shell is one of the most significant WordPress Core security events in recent years," Wordfence said. "The combination of unauthenticated reachability, no plugin or theme requirement, a large global attack surface, a path to administrator access and code execution, as well as public proof-of-concept exploit availability makes this vulnerability chain unusually serious." Attack data captured by the WordPress security company shows that threat actors are issuing requests to exploit the REST API batch request route-confusion issue and an unauthenticated SQL injection to achieve code execution. VulnCheck also said it had verified more than two-dozen unique PoC exploits targeting WP2Shell as of July 19, 2026. "Affected users should update to a fixed version of WordPress as soon as possible, given the overwhelming likelihood that various public exploits and large-scale exploitation will follow the high-profile disclosure," it added. As for CVE-2026-0770, KEVIntel's Ryan Dewhurst told The Hacker News that first in-the-wild attack efforts targeting the flaw were detected against its sensors on June 27, 2026, recording 137 exploitation attempts from 46 unique attacker IP addresses associated with 17 countries since then. No less than 75 attempts, which account for more than half of the activity, originated from 20 attacker IP addresses during the last seven days. Observed payloads include base command execution checks, attempts to extract the contents of "/etc/passwd" or access AWS credentials, environment variable collection, malware downloads using wget or curl, and shell script execution to install second-stage payloads. "The activity is not limited to vulnerability checks," Dewhurst said. "While much of it involved commands such as id, whoami and reading /etc/passwd, we also observed payloads attempting to download malware and obtain environment variables, AWS credentials and container metadata." Federal Civilian Executive Branch (FCEB) agencies are advised to remediate the identified flaws by July 24, 2026.
thehackernews.comJul 22, 2026extracted
Zimbra Update Patches Critical Vulnerabilities
Zimbra on Monday announced patches for several critical-severity vulnerabilities, including a command injection bug disclosed in late June. The critical command injection impacts the SNMP monitoring component of the collaboration suite if SNMP notifications are enabled and the integrated Swatchdog service is running. An unauthenticated attacker could send crafted payloads to execute arbitrary OS commands in the background and compromise the email server. Zimbra Collaboration Suite (ZCS) version 10.1.20 includes a permanent fix for the bug. The update also patches four cross-site scripting (XSS) defects in the Classic Web Client (Classic UI) that could lead to script execution under certain conditions. The flaws can be exploited via malicious attachment filenames, crafted fields, and crafted attachments. It also resolves CVE-2026-50055, a mail forwarding restriction bypass where authenticated attackers could exfiltrate emails even if mail forwarding restrictions are enabled. Additionally, it resolves an access control vulnerability in the EWS extension (CVE-2026-10631), an authorization issue in mailbox delegation (CVE-2026-50054), and a server-side request forgery (SSRF) bug in the Nextcloud integration. Zimbra has refrained from sharing further details on these security defects, but urges users to update to ZCS 10.1.20 as soon as possible. However, it makes no mention of any of these issues being exploited in the wild. The fresh security update arrived roughly two weeks after Zimbra patched a critical XSS security bug in the Classic Web Client that could lead to code execution when opening an email. Related: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Related: OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Related: Chrome 150 Update Patches Severe Memory Safety Bugs Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild
securityweek.comJul 21, 2026extracted
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to FortiBleed's infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment for the first time," SOCRadar said in a new report published Wednesday. The company said it tracked scanning activity against approximately 11,250 FortiGate portals in more than 150 countries, followed by confirmed admin-level access on 409 targets and successful completion of the full attack chain on 354 of them. In all, at least 12 ransomware deployments have resulted from this access, causing hundreds of endpoints to be encrypted across affected organizations. The large-scale credential-harvesting operation, which came to light last month, involved the threat actors systematically scanning the internet for exposed Fortinet devices, attempting to break into them using known credential combinations, and then deploying custom packet sniffers to passively gather credentials and other authentication data from network traffic. The campaign is assessed to have targeted 430,000 FortiGate firewalls globally, gathering over 110 million credentials in the process. The activity was exposed after an operational security error on the part of the attackers left a server containing credentials stolen from thousands of Fortinet appliances exposed on the internet. The Golang sniffer is estimated to have been installed on about 12,000 Fortinet devices, making it a subset of the total number of networking gear targeted. The latest findings from SOCRadar show that an operator with access to FortiBleed infrastructure was found logged in to both INC Ransom and Lynx negotiation panels, with victims listed by INC Ransom overlapping with data from the campaign. The links are based on one of the 200 newly discovered servers associated with the FortiBleed infrastructure that granted visibility into internal files, logs, and operational documentation. Ensar Seker, chief information security officer at SOCRadar, told The Hacker News via email that the exposed server functioned as a staging staging and operational coordination server, and was not used for phishing or active credential collection. "It contained target inventories, harvested data, automation scripts, configuration files, and operational artifacts that indicate it was used to coordinate large-scale credential harvesting against internet-facing network appliances," Seker said. "In other words, it served as part of the attackers’ backend infrastructure rather than the infrastructure victims directly interacted with." Tooling, logs, and working hours indicate that the activity is the work of a Russian-speaking threat actor who likely operates as an initial access broker. Much of the targeting has singled out manufacturing, technology, and logistics sectors in Latin America and the Asia Pacific regions. SOCRadar also said it discovered an internal document that indicates it's an organized operation comprising about 20 people with a clear division of labor. "A small core of lead operators drives most high-impact intrusions, backed by specialists and support staff," it added. In addition, the threat actors are believed to be in possession of at least one zero-day vulnerability in Nextcloud. The threat intelligence firm said it's actively coordinating with the affected vendor. The Delaware-based company said it also identified Citrix-related artifacts that indicate the activity is likely targeting beyond Fortinet devices. The identified infrastructure included a dedicated target list containing about 29,000 IP addresses and 37 domains associated with Citrix environments. This suggests the automated workflow may be repurposed for other remote access technologies. "At this stage, the presence of these target lists does not conclusively prove that credential harvesting against Citrix devices has already occurred at scale," Seker explained. "Rather, it demonstrates clear reconnaissance and targeting preparations." "However, given the sophistication of the infrastructure and the operators proven ability to automate credential collection against Fortinet devices, organizations using internet-facing Citrix infrastructure should treat this as an early warning and verify authentication logs, rotate exposed credentials where appropriate, enforce MFA, and monitor for anomalous login activity." The disclosure comes as eSentire said it observed threat actors exploiting a flaw in Fortinet FortiClient EMS (CVE-2026-35616, CVSS score: 9.1) to deploy an information stealer called EKZ Stealer against a customer in the energy, utilities, and waste sector with the end goal of harvesting credentials from Chromium-based browsers and Firefox and exfiltrating them via PowerShell.
thehackernews.comJul 2, 2026extracted
FortiBleed credential-theft campaign linked to Lynx ransomware
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. Earlier this month, a server containing credentials stolen from more than 73,000 Fortinet devices was discovered exposed on the internet. Researchers found the server contained downloaded FortiGate configuration files, credentials harvested from compromised devices, and infrastructure used to crack password hashes and perform credential-stuffing attacks. The campaign was dubbed "FortiBleed" due to the large number of exposed credentials and the massive credential-theft operation. Follow-up investigations by SOCRadar revealed that the operation used a custom packet-sniffing tool called "FortiGate Sniffer" on compromised FortiGate firewalls, allowing attackers to intercept VPN credentials and other authentication data directly from network traffic. SOCRadar's Threat Research Unit (STRU) latest research now ties the credential theft operation directly to members of the INC and Lynx ransomware-as-a-service (RaaS) groups. The researchers told BleepingComputer that they discovered this link after identifying a Windows server used as part of the FortiBleed infrastructure. "Our threat researchers identified a Windows server belonging to the FortiBleed infrastructure, which provided further insight into the threat actors' modus operandi," SOCRadar told BleepingComputer. "During the investigation of that server, analysis of the collected artifacts revealed that the threat actor had accessed the ransomware negotiation panels of both the Lynx / INC ransomware group." SOCRadar shared screenshots with BleepingComputer showing browser sessions accessing the administration panels for both ransomware groups. The images show negotiation dashboards containing victim chats used during ransomware negotiations. According to the researchers, this provides direct evidence that an individual with access to FortiBleed infrastructure was also involved with the ransomware groups' negotiation platforms. The company also says it identified more than 200 additional operational servers beyond those originally associated with the campaign, discovered victim information harvested during FortiBleed that overlaps with organizations later listed on the INC ransomware leak site, and uncovered evidence suggesting the operation consists of roughly 20 members with defined roles. SOCRadar also says the campaign was considerably larger than originally understood. According to the researchers, the operation targeted more than 430,000 FortiGate firewalls worldwide and deployed traffic sniffers on approximately 19,000 devices. After notifying impacted organizations, the number has fallen to around 11,000 compromised devices. The researchers also say they identified roughly 500 servers used by the operation. The researchers also believe the attackers exploited a previously undisclosed Nextcloud zero-day vulnerability as part of their operations to expand access after initial compromise. However, technical details have not yet been released. SOCRadar also told BleepingComputer it found persistent backdoor accounts using the username "adminin" on compromised systems and is continuing efforts to recover ransomware decryption keys. INC Ransom has operated as a ransomware-as-a-service platform since mid-2023, targeting organizations across healthcare, education, government, and other sectors worldwide. Lynx emerged in mid-2024 and is believed by security researchers to be a rebrand of the INC ransomware gang rather than a new extortion group. SOCRadar says a second technical white paper containing indicators of compromise, attribution evidence, and additional technical analysis will be released once its investigation is complete. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 1, 2026extracted
PixelSmash flaw turns video files into attack tools
A newly discovered vulnerability in FFmpeg’s MagicYUV decoder can turn a tiny, malformed video into a foothold for attackers. Researchers have disclosed PixelSmash, a critical vulnerability tracked as CVE-2026-8461, in FFmpeg’s MagicYUV video decoder with a CVSS score of 8.8. By crafting a specially formatted AVI, MKV, or MOV file, an attacker can crash or potentially execute code on any system that tries to generate a thumbnail, extract metadata, or play the file with a vulnerable version of FFmpeg. What is FFmpeg and is this serious? FFmpeg is an open‑source toolkit for recording, converting, and streaming audio and video, and its libavcodec library implements hundreds of audio and video decoders. One of those is MagicYUV, a lossless codec popular in video editing workflows and, crucially, enabled by default in upstream FFmpeg and all the Linux distribution packages the researchers tested up to FFmpeg 9.0. The impact is more serious than you may think. If you run anything that touches video—from a Linux desktop to a Jellyfin or Nextcloud server, or even an AI model that ingests clips—you probably rely on FFmpeg under the hood. It’s hard to put an exact number on how many systems are affected, but it helps to know that: Tens of millions of Linux systems rely on ffmpegthumbnailer and systemlibavcodec for thumbnails, meaning “just browsing a folder” can trigger the bug if a malicious file is present. Jellyfin and Nextcloud, among the most popular self‑hosted media and file platforms globally, each have at least tens of thousands of active internet‑reachable servers. Almost all of those that did not update FFmpeg or disable MagicYUV are vulnerable to denial of service (DoS) and, in some configurations, targeted remote code execution (RCE) attacks. A large fraction of consumer network attached storage (NAS) and smart TV platforms use FFmpeg for previews and thumbnails. These devices are sold in the millions. The most worrying part of PixelSmash is how little it takes to trigger it. All you need is an application that uses FFmpeg to process untrusted media and has the MagicYUV decoder compiled in. PixelSmash is a good illustration of a broader problem in the open‑source ecosystem: a bug in a deep dependency that silently propagates everywhere. How to protect yourself This vulnerability is not something most home users need to worry about. It needs to be taken care of upstream. Users of affected Linux distributions should keep an eye out for FFmpeg updates or security updates from their distro. But if you’re responsible for systems that handle video, you should assume you are affected until you prove otherwise. The main mitigation steps are: Update FFmpeg. FFmpeg version 8.1.2, released on June 17, 2026, includes a fix for CVE‑2026‑8461. If your distribution or vendor provides an updated FFmpeg, install it across desktops, servers, and containers. Check if MagicYUV is enabled and disable it or apply patches where possible. Reduce automatic processing of untrusted video. Review which preview providers and thumbnailers are enabled, especially for rarely used formats. Finally, it is worth watching for abnormal crashes of media players, thumbnailers, or media servers, especially after opening or downloading a new video file. You should treat repeated crashes or missing thumbnails as potential indicators of malicious content until systems are patched. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comJun 24, 2026extracted
FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
A vulnerability in the FFmpeg media processing framework allows attackers to crash applications and execute arbitrary code remotely, JFrog warns. FFmpeg is used in most media-processing applications across every platform, including desktop video players, Linux file managers, self-hosted media servers, and cloud transcoding pipelines. Tracked as CVE-2026-8461 (CVSS score of 8.8), the security defect is described as a heap out-of-bounds write within FFmpeg’s libavcodec library, in the MagicYUV decoder. The flaw exists in the MagicYUV decoder’s slice handling and is “caused by an inconsistency between how the frame allocator and the decoder compute chroma plane heights,” JFrog explains. Dubbed PixelSmash, it can be exploited to crash any application that uses FFmpeg. Code execution can be achieved by targeting FFmpeg’s AVBuffer struct, a refcounted buffer management object allocated immediately after each plane’s pixel data. To gain code execution, an attacker needs to target FFmpeg’s AVBuffer struct, a refcounted buffer management object allocated immediately after each plane’s pixel data. According to JFrog, by placing a NUL-terminated shell command at a specific out-of-bounds offset, an attacker can obtain shell execution before the FFmpeg process crashes on subsequent heap corruption. PixelSmash can be exploited for remote code execution (RCE) via crafted media files delivered to any application that uses FFmpeg’s libavcodec for video decoding. On desktop, the vulnerability is triggered when the user opens the malicious file in a video player, or when they browse to a folder containing it, if the file manager’s thumbnail generator uses the vulnerable library. Code execution on a server is achieved when the media file is uploaded to a media server, chat platform, or cloud transcoding service, which automatically processes it. The bug can also be exploited on NAS appliances, media appliances, and smart TVs that generate video thumbnails or previews. “No authentication, special privileges, or prior access to the target system is required beyond the ability to deliver a media file – the default attack surface for any media-processing application,” JFrog explains. The exploit payload can be delivered as a 50 KB AVI, MKV, or MOV file. It can be used in zero-click attacks over torrents if the victim has their torrent client set to download media files directly into a monitored media library folder. As soon as the torrent finishes, the automated library scanning executes the payload. On the self-hosted cloud storage platform Nextcloud, which uses an independent FFmpeg build, the vulnerability can be triggered via the optional Movie preview provider, which invokes the system FFmpeg binary to generate thumbnails. “The attacker requires no interaction beyond ensuring the file is visible in a folder listing; the server-side processing handles the rest, making this a near-zero-click vector,” JFrog notes. The cybersecurity firm confirmed successful exploitation of the bug against Kodi, mpv, ffmpegthumbnailer (used by GNOME, KDE, XFCE), Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio. It also demonstrated successful RCE against Jellyfin. FFmpeg version 8.1.2 contains fixes for PixelSmash. Users are advised to update as soon as possible. Related: Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data Related: Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones Related: Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
securityweek.comJun 23, 2026extracted
FFmpeg fixes PixelSmash flaw in widely used video decoder
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. The vulnerability is tracked as CVE-2026-8461 and is a heap out-of-bounds write in the MagicYUV decoder. It received a high-severity score of 8.8 and can be leveraged via a malicious video file in AVI, MKV, or MOV format. Any application that uses libavcodec, FFmpeg’s core library for video decoding and encoding, is considered vulnerable. However, exploitation for remote code execution (RCE) is possible if the Address Space Layout Randomization (ASLR) defense is disabled or by chaining another vulnerability to defeat the protection. Root cause and impact Researchers at software supply-chain security company JFrog say that PixelSmash stems from the way MagicYUV processes slices, independent regions of a video frame that can be decoded separately from the rest of the image. "The vulnerability is a one-row heap buffer overflow in the MagicYUV decoder’s slice handling, caused by an inconsistency between how the frame allocator and the decoder compute chroma plane heights," JFrog explains. PixelSmash can be triggered when the user opens AVI, MKV, or MOV video files, browses a directory containing the file (via thumbnail generation), or runs any automated media ingestion workflow. JFrog found that multiple popular media applications, such as Kodi, OBS Studio, PhotoPrism, and GNOME/KDE/XFCE’s thumbnail generators, use FFmpeg with the MagicYUV decoder enabled, making them vulnerable to PixelSmash attacks. Slack, Discord, Telegram, and WhatsApp may also be susceptible to PixelSmash attacks, as they use FFmpeg to generate server-side video previews, but they were not tested. JFrog lead researcher Yuval Moravchick demonstrated that PixelSmash can be used for remote code execution on Jellyfin and Nextcloud (with Movie preview enabled) instances. “To demonstrate the real-world impact, we achieved full remote code execution against a Jellyfin 10.11.9 media server - the second-most popular self-hosted media server (after Plex) - through its normal media library scan pipeline,” JFrog says. “Attack path: a download of a crafted MagicYUV AVI into the media library -> Jellyfin automatically triggers ffprobe for metadata extraction -> the OOB write fires -> AVBuffer.free is hijacked to system() -> arbitrary command executes as the jellyfin service user.” However, Moravchick noted that the RCE exploit requires ASLR (Address Space Layout Randomization) to be disabled, and that CVE-2026-8461 alone does not bypass this memory protection. In theory, a separate information-disclosure bug in FFmpeg's FlashSV decoder could be chained with PixelSmash to bypass ASLR. Another attack scenario is via torrent downloads and requires no user interaction. The researchers say that an attacker could seed a malicious video that targets Jellyfin users who point the download to the application's media library folder. "Jellyfin’s real-time file system monitor detects the new file and automatically triggers an ffprobe metadata scan. The exploit fires during the scan - AVBuffer.free is hijacked to system(), and the attacker’s reverse shell command executes as the jellyfin service user" Even when RCE is prevented or impossible, the CVE-2026-8461 vulnerability should be sufficient to reliably achieve a denial-of-service (DoS) condition on vulnerable targets. The researchers found that Plex, the massively popular media server, uses a custom FFmpeg build in which decoders are disabled and a minimal allowlist is in effect, effectively mitigating the PixelSmash risk. Apart from FFmpeg releasing version 8.1.2, which fixes the flaw, Jellyfin also updated its bundled FFmpeg version, and PhotoPrism is working to add a file format blocklist to prevent potential exploitation. The Nextcloud team received the report via HackerOne, but declined to address the flaw because it exists outside of Nextcloud. JFrog discovered PixelSmash (CVE-2026-8461) and reported it to the FFmpeg security team on May 13. The developer addressed the issue in version 8.1.2, released on June 17. The researchers warn that PixelSmash has a huge attack surface because the MagicYUV decoder is present in hundreds of projects that "trust FFmpeg to handle untrusted input safely," turning the vulnerability into a supply-chain problem. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 22, 2026extracted
The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne
The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne Trisquel GNU/Linux, a free operating system aimed at home users, small enterprises, and educational centers, released version 12.0. The release, codenamed Ecne, is declared production-ready and builds on the previous version, Aramo, with changes to packaging, the kernel, security, and available software. APT 3.0 and repository format changes Ecne ships with APT 3.0, which brings adoption of the deb822 repository format across all installation paths. The change covers the text-based netinstall, the graphical Ubiquity installer, and package-management tools including Synaptic. The deb822 format replaces the older repository format used in prior releases. Kernel and installer work The kernel remained, in the project’s own words, one of its biggest engineering challenges. For Ecne, the team focused on making kernel changes more modular, which substantially reduced breakage in the udeb components used during installation. Work on updating kernel-wedge is ongoing, with the project reporting it is well positioned to complete it. AppArmor rules and LXDE The team revised many AppArmor rules for graphical environments, extending security coverage for desktop use. The Trisquel Mini edition, which runs the LXDE desktop, received a significant number of upstream improvements. Ubuntu dropped LXDE from all its releases, leaving Trisquel as one of its primary maintained homes. Browser choices Ecne adds ungoogled-chromium and IceCat to its software offerings. Both join Abrowser, the distribution’s continuously maintained browser, giving users three web browsing options that meet the project’s free software requirements. Backports repository The backports repository continues to deliver applications in recent versions. The current list includes LibreOffice, yt-dlp, Inkscape, Nextcloud Desktop, Kdenlive, Tuba, 0 A.D., and fastfetch, among others. Editions Ecne ships in five editions. The default Trisquel edition uses MATE version 1.26.1 and does not require 3D graphics acceleration. Triskel offers KDE Plasma version 5.27 for users who want detailed control over the desktop environment. Trisquel Mini runs LXDE version 0.99.2 and targets netbooks, older computers, and users with low resource requirements. Trisquel Sugar, also called Trisquel On A Sugar Toast (TOAST), is based on the Sugar learning platform version 0.121 and includes educational activities for children. A network installer image rounds out the lineup, suited to servers and advanced users who want a command-line installation. Must read: 40 open-source tools redefining how security teams secure the stack Firmware scanning time, cost, and where teams run EMBA Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comApr 12, 2026extracted
Little Snitch for Linux shows what your apps are connecting to
Little Snitch for Linux shows what your apps are connecting to Network monitoring on Linux has long been a gap for users who want per-process visibility into outbound connections. Existing tools either operate at the command line or were designed for server security rather than desktop privacy. Objective Development, the Austrian company behind the macOS firewall utility Little Snitch, released a Linux version of the tool. It is free and, according to the company, will remain so. Architecture choices The kernel component uses eBPF for traffic interception. eBPF operates at the kernel level and offers greater portability than kernel extensions. The main backend is written in Rust. The user interface is a web application, which means a Linux server running Little Snitch can be monitored remotely from any device, including a Mac. The company lists server applications such as Nextcloud, Home Assistant, and Zammad as practical use cases for this capability. The kernel component and the UI are open source. The kernel code is released so users can review its implementation, fix bugs, or adapt it to different kernel versions. The UI is licensed under GPL v2. The backend, which manages rules, block lists, and the connection view hierarchy, is free to use but closed source. Feature scope and security limits “From a feature perspective, Little Snitch for Linux sits somewhere between Little Snitch Mini and the full Little Snitch: functional and useful, but without all the polish and depth of the macOS version. Think of it as an honest first version,” the company said. eBPF operates under resource constraints that make it possible to bypass the firewall, for example by flooding its tables. The tool is designed to show users what legitimate software is connecting to and to block those connections where desired. It is not designed to stop software that is actively attempting to evade it. Compatibility The release is confirmed to work on kernel 6.12 and above. On older kernels, the tool currently hits the eBPF verifier’s maximum instruction limit. The company states that compatibility down to kernel 5.17, where the bpf_loop() function was introduced, is theoretically achievable. Kernel 5.17 compatibility would extend support to Debian 12 (Bookworm) and Ubuntu 24.04 LTS (Noble). The company is inviting contributions from developers with the expertise to close that gap. Little Snitch for Linux is available on GitHub. Must read: 40 open-source tools redefining how security teams secure the stack Firmware scanning time, cost, and where teams run EMBA Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comApr 10, 2026extracted
European Commission Confirms Cloud Data Breach
The European Commission has admitted that hackers may have taken data from the cloud infrastructure hosting its Europa.eu platform. The executive body released a statement on March 27 confirming it had discovered the cyber-attack on March 24 and took “immediate steps” to investigate and contain the breach. “The commission's swift response ensured the incident was contained and risk mitigation measures were implemented to protect services and data, without disrupting the availability of the Europa websites,” it continued. “Early findings of our ongoing investigation suggest that data have been taken from those websites. The commission is duly notifying the Union entities who might have been affected by the incident. The commission's services are still investigating the full impact of the incident.” The commission said that its “internal systems” were not impacted by the attack, and that it will continue to monitor the situation, analyze the incident and use any findings to “further enhance its cybersecurity capabilities.” According to screenshots posted to X (formerly Twitter), extortion group ShinyHunters claims to have compromised over 350GB of European Commission data, including data dumps of mail servers, databases, confidential documents, contracts, and much more sensitive material. Separate screenshots allegedly posted by ShinyHunters appear to show the personally identifiable information (PII) of employees. Security researchers at the International Cyber Digest claimed that the hackers compromised emails, DKIM signing keys, internal admin URLs, and data from content collaboration platform NextCloud and military financing mechanism Athena. A full single sign on (SSO) user directory may also have been taken. ShinyHunters On the Prowl ShinyHunters is a prolific hacking group with a string of big-name victims. Its most noteworthy campaign targeted SSO credentials and Salesforce data at Google, Chanel, Pandora, Panera Bread, Match Group and scores of other organizations last year. It followed that up with another campaign earlier this month targeted Experience Cloud websites. The group specializes in vishing – and in some attacks it impersonates the IT helpdesk in calls to victims, tricking them into entering their credentials into phishing sites spoofed to look like legitimate corporate portals. It’s unclear how the European Commission was breached. Reports suggest the incindent involved data hosted in the commission's AWS environment, although the cloud provider has confirmed to Infosecurity that its services were not compromised. Unconfirmed chatter on social media suggested EU security agency ENISA may also have been hit. Nick Tausek, lead security automation architect at Swimlane, argued that the breach could open the door to identity risk, operational disruption and secondary spear-phishing attacks. “The attacker claiming they will not extort does not make it less serious, it just changes the playbook,” he added. “A quiet leak can be just as damaging for trust, diplomacy, and ongoing investigations, and it forces defenders into a messy mix of containment, forensics, and communications while the organization is still determining what was breached and what is still exposed.”
infosecurity-magazine.comMar 30, 2026extracted
ownCloud urges users to enable MFA after credential theft reports
File-sharing platform ownCloud warned users today to enable multi-factor authentication (MFA) to block attackers using compromised credentials from stealing their data. ownCloud has over 200 million users worldwide, including hundreds of enterprise and public-sector organizations such as the European Organization for Nuclear Research, the European Commission, German tech company ZF Group, insurance firm Swiss Life, and the European Investment Bank. In a security advisory published today, the company urged users to enable MFA following a recent report from Israeli cybersecurity company Hudson Rock, which revealed that multiple organizations had their self-hosted file sharing platforms (including some ownCloud Community Edition instances) breached in credential theft attacks. "The ownCloud platform was not hacked or breached. The Hudson Rock report explicitly confirms that no zero-day exploits or platform vulnerabilities were involved," ownCloud said. "The incidents occurred through a different attack chain: threat actors obtained user credentials via infostealer malware (such as RedLine, Lumma, or Vidar) installed on employee devices. These credentials were then used to log in to ownCloud accounts that did not have Multi-Factor Authentication (MFA) enabled." ownCloud advised users to immediately enable MFA on their ownCloud instance to secure their data against future attacks and prevent unauthorized access even when their credentials are compromised. Additionally, ownCloud recommends resetting all user passwords, invalidating all active sessions to force re-authentication, and reviewing access logs for suspicious login activity. This warning comes after a threat actor (known as Zestix) has been offering to sell corporate data stolen from dozens of companies, likely obtained after breaching their ShareFile, Nextcloud, and ownCloud instances. In its January 5th report, Hudson Rock says the attackers may have obtained initial access to the companies' file-sharing servers using credentials stolen by infostealer malware such as RedLine, Lumma, and Vidar, which infected employee devices. The cybercrime intelligence firm identified thousands of infected computers, including some on the networks of high-profile organizations like Deloitte, KPMG, Samsung, Honeywell, Walmart, and the U.S. CDC (Centers for Disease Control and Prevention). Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJan 7, 2026extracted
MFA Failure Enables Infostealer Breach At 50 Enterprises
Dozens of global organizations have had highly sensitive corporate and customer information stolen and put up for sale by a threat actor because they didn’t secure cloud systems with multi-factor authentication (MFA), a new report has revealed. The actor, known as “Zestix” (aka “Sentap”) scoured the dark web for infostealer logs containing credentials for popular cloud file sharing services ShareFile, Nextcloud and OwnCloud, according to Hudson Rock. He was subsequently able to access, exfiltrate and auction the data stored in these accounts, due to a lack of MFA, the cybersecurity vendor said. “A critical finding in this investigation is the latency of the threat. While some credentials were harvested from recently infected machines, others had been sitting in logs for years, waiting for an actor like Zestix to exploit them,” Hudson Rock explained. “This highlights a pervasive failure in credential hygiene; passwords were not rotated, and sessions were never invalidated, turning a years-old infection into a present-day catastrophe.” The credentials were originally obtained via a number of infostealer variants, including RedLine, Lumma and Vidar. “Because the organizations […] did not enforce MFA, the attacker walks right in through the front door. No exploits, no cookies – just a password,” noted Hudson Rock. The financially motivated threat actor apparently appears to be comfortable interacting on closed Russian cybercrime forums, where he presents as an initial access broker (IAB). However, the Sentap persona has also been linked to an Iranian national and is affiliated with the Funksec cybercrime group, the report claimed. A Roll Call of Victims Among the organizations caught out by Zestix and named in the report are: Iberia Airlines, which had 77GB of technical safety and fleet data stolen Burris & Macomber, a law firm acting as counsel for Mercedes-Benz USA, which spilled over 18GB of customer data, corporate secrets and info on litigation strategy Maida Health, a Brazilian firm which had over 2TB of health records relating to the Brazilian Military Police stolen Intecro Robotics, a Turkish defense manufacturer, which had over 11GB of military IP stolen “The rise of the Zestix threat actor paints a grim picture for 2026: major enterprise breaches are succeeding without needing sophisticated zero-day exploits,” argued Xcape’s John Carberry. “Someone can take 77 GB of flight maintenance data with a three-year-old password. That's not ‘hacked’ security; that’s ignored security.” Image credit: Fasttailwind / Shutterstock.com
infosecurity-magazine.comJan 7, 2026extracted
Dozens of Major Data Breaches Linked to Single Threat Actor
Several major data breaches are linked to a threat actor who relies on stolen credentials to compromise enterprise networks, Hudson Rock reports. Operating under the moniker ‘Zestix’ but also linked to the online persona ‘Sentap’, the threat actor is an initial access broker (IAB) who was also seen exfiltrating victim data and selling it on hacker forums. According to Hudson Rock, Zestix emerged as a distinct entity in late 2024-early 2025, but its activities can be linked to Sentap operations that have been ongoing since 2021. Both personas can be linked to information-stealer infections resulting in the compromise of global enterprises operating in the aerospace, government infrastructure, legal, and robotics sectors. The credentials, Hudson Rock says, were harvested from the personal or work devices of employees at the victim organizations using information stealers such as RedLine, Lumma, and Vidar. “While some credentials were harvested from recently infected machines, others had been sitting in logs for years, waiting for an actor like Zestix to exploit them,” Hudson Rock notes. The lack of multi-factor authentication (MFA) protections on accounts with access to file-transfer instances such as ShareFile, OwnCloud, and Nextcloud has allowed Zestix/Sentap to use the compromised credentials successfully on roughly 50 occasions. The exfiltrated data is then offered for sale on closed Russian-language forums, but Zestix was also seen selling access to the compromised systems. Zestix/Sentap victims According to Hudson Rock, Zestix has established a reputation for reliability. This explains why they were asking $150,000 for the 77 GB of data allegedly stolen from Iberia, the Spanish flag carrier. Other victims include Pickett & Associates (an engineering firm serving energy organizations), Intecro Robotics (aerospace and defense equipment maker), Maida Health (serves the Brazilian military police), CRRC MA (rolling stock maker subsidiary), K3G (Brazilian ISP), NMCV Business LLC (manages data for US healthcare facilities), and over a dozen others. Under the Sentap moniker, the threat actor built a wider list of victims, but Hudson Rock says it could not link these breaches to file-sharing services or infostealer infections. “It is possible that they still stem from similar Infostealer credentials based on the high number of victims we did identify to have infostealer credentials to those services, but we do not rule out access via another initial access,” Hudson Rock says. The threat actor has claimed massive breaches at Pan-Pacific Mechanical (1.04 TB), Bradley R. Tyer & Associates (1.02 TB), The Providence Group (1 TB), Australian NBN (306 GB), UrbanX.io (275 GB), and dozens of others. The infostealer problem According to Hudson Rock, credentials pertaining to thousands of organizations that use ShareFile, OwnCloud, and Nextcloud are circulating in infostealer logs, including those of prominent names such as Deloitte, Honeywell, KPMG, Samsung, and Walmart. “These organizations have employees or partners who have been infected, leaving valid sessions or credentials to sensitive file repositories exposed to actors like Zestix,” the cybersecurity firm notes. The issue, however, has been around for a long time and is unlikely to be easily resolved. The information stealer industry is fueling modern cybercrime, acting as the starting point for data breaches, identity theft, and fraud. “Stealers are an example of the commodification of cybercrime delivered through malware-as-a-service (MaaS),” SpyCloud Labs SVP of security research Trevor Hilligoss said in a discussion with SecurityWeek. “You no longer need to be a skilled developer or hacker to gain access to tools that are incredibly effective when deployed at scale. Anyone can just buy or hire readymade malware from the MaaS marketplace,” Hilligoss added. The success of information stealers builds on speed and stealth. They exfiltrate sensitive information in minutes and are often removed from the infected devices immediately after, leaving minimal traces of wrongdoing. And for over a decade, stolen credentials have fueled massive attack campaigns, including credential stuffing attacks, which continue to be a problem. Related: NordVPN Denies Breach After Hacker Leaks Data Related: Brightspeed Investigating Cyberattack Related: Sedgwick Confirms Cyberattack on Government Subsidiary Related: Thousands of Secrets Leaked on Code Formatting Platforms
securityweek.comJan 6, 2026extracted
Cloud file-sharing sites targeted for corporate data theft attacks
A threat actor known as Zestix has been offering to sell corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances. According to cybercrime intelligence company Hudson Rock, initial access may have been obtained through credentials collected by info-stealing malware such as RedLine, Lumma, and Vidar deployed on employee devices. The three infostealers are usually distributed through malvertising campaigns or ClickFix attacks. This type of malware commonly targets data stored by web browsers (credentials, credit cards, personal info), messaging apps, and cryptocurrency wallets. A threat actor with valid credentials can gain unauthorized access to a service, such as a file-sharing platforms, when multi-factor authentication (MFA) protection is missing. In a report today, Hudson Rock notes that some of the analyzed stolen credentials have been present in criminal databases for years, indicating failure to rotate them or to invalidate active sessions even after extended periods. Multiple breaches advertised Hudson Rock says that Zestix operates as an initial access broker (IAB) on underground forums, selling access to high-value corporate cloud platforms. The cybersecurity company suggest that attackers breached ShareFile, Nextcloud, and ownCloud environments used by organizations across multiple sectors, including aviation, defense, healthcare, utilities, mass transit, telecommunications, legal, real estate, and government. After parsing infostealer logs "specifically looking for corporate cloud URLs (ShareFile, Nextcloud)," the threat actor logs into the file-sharing services using a valid username and password where MFA is not active. Hudson Rock says it pinpointed the likely breach points by correlating infostealer data from its platform with publicly available images, metadata, and open-source information. In at least 15 of the analyzed cases, the cybersecurity company found that employee credentials for the cloud file-sharing services had been collected by infostealers. It is important to note that this verification is unilateral, and there’s no public confirmation of a security breach from the listed companies. One exception could be Iberia, although its recent disclosure isn't necessarily linked to Hudson Rock's findings. Zestix offered to sell stolen data volumes that range from tens of gigabytes to several terabytes, claiming to include aircraft maintenance manuals and fleet data, defense and engineering files, customer databases, health records, mass-transit schematics, utility LiDAR maps, ISP network configs, satellite project data, ERP source code, government contracts, and legal documents. Many of the allegedly stolen files could expose organizations to security, privacy, and industrial espionage risks, while exposed government contracts may raise national security concerns. Hudson Rock has found an additional set of 30 victims that Zestix sells under the alias “Sentap,” but the researchers did not validate it in the same way. The researchers report that, in addition to the listed victims, their threat intelligence data indicates that cloud exposure is a broader, systemic problem stemming from organizations’ failure to follow good security practices. They report having identified thousands of infected computers, including some at Deloitte, KPMG, Samsung, Honeywell, and Walmart. Hudson Rock told BleepingComputer that it has notified ShareFile and will also alert Nextcloud and OwnCloud about the verified exposures so they can take the appropriate action. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJan 5, 2026extracted
Il Parlamento Europeo vuole sganciarsi da Microsoft e dai software Usa
In una lettera indirizzata al Presidente Roberta Metsola, 38 eurodeputati hanno chiesto l’abbandono di Microsoft e delle tecnologie Usa per il Parlamento comunitario, a favore di quelle europee. Tra queste il browser Internet norvegese Vivaldi, il motore di ricerca francese Qwant, la posta elettronica svizzera Proton e la piattaforma tedesca Nextcloud. Il Parlamento Europeo vuole sganciarsi da Microsoft e dai software Usa, puntando in maniera sistemica sulla tecnologia europea. In una lettera indirizzata al Presidente Roberta Metsola, 38 europarlamentari hanno chiesto l’abbandono delle tecnologie “made in Usa” a favore di quelle europee. Tra queste, il browser Internet norvegese Vivaldi, il motore di ricerca francese Qwant, la posta elettronica svizzera Proton e la piattaforma tedesca Nextcloud. “Nel documento“, scrive POLITICO – che ha visionato la lettera in anteprima – “i 38 legislatori hanno elencato anche gli schermi, le tastiere e i mouse di Dell, HP e LG. Sono tutti in uso nei sistemi informatici della camera, come tecnologie da abbandonare“. Per i parlamentari il dominio dei giganti tecnologici statunitensi non serve più ad avere costi efficienti, ma è ormai un rischio per la sicurezza e la prosperità dell’Europa. Il tutto, mentre l’Amministrazione Usa ha rinnovato le richieste di concessioni digitali in occasione di una riunione tenutasi lunedì scorso, proprio a Bruxelles. L’importanza dei firmatari La riflessione è destinata a far discutere, vista l’importanza dei suoi estensori. Tra i firmatari della lettera, infatti, hanno trovato spazio quasi tutte le famiglie politiche dell’Unione. Dal PPE con Aura Salla e Mika Aaltola, ai socialdemocratici Birgit Sippel e Raphaël Glucksmann (S&D). Presenti anche i centristi di Renew Europe Stéphanie Yon-Courtin e Marie-Agnes Strack-Zimmermann. Più a sinistra, ecco i Verdi con Alexandra Geese e Kim van Sparrentak e gli esponenti della Sinistra Leïla Chaibi e Merja Kyllönen. Un nuovo corso tecnologico europeo? Nella lettera, si legge anche: “Il Parlamento Europeo è nella posizione ideale per dare impulso alla sovranità tecnologica. Quando anche i vecchi amici possono trasformarsi in nemici e le loro aziende in uno strumento politico, non possiamo permetterci questo livello di dipendenza dalla tecnologia straniera. Né tanto meno continuare a convogliare miliardi di denaro dei contribuenti all’estero”. In termini di risultati, “l’obiettivo a medio termine dovrebbe essere la completa eliminazione dei prodotti Microsoft, compreso il sistema operativo Windows. È più facile di quanto sembri”. D’altronde, come hanno evidenziato, “i dispositivi che utilizziamo in questa sede sono quasi tutti di marche europee“. Per questo, la medesima impostazione “si può replicare per l’hardware dei computer di produzione finale“. Di qui, la richiesta di istituire un gruppo di lavoro interno per aiutare e monitorare tale transizione. “Con una volontà politica sufficiente“, hanno affermato gli eurodeputati, “avremo liberato questa istituzione dal pericolo della dipendenza dalla tecnologia straniera entro la fine del mandato”. La replica di Microsoft La scorsa settimana, nelle stesse ore in cui la Commissione Europea ha varato il Digital Omnibus, in Germania si è tenuto un vertice di alto livello sulla sovranità tecnologica. La Francia ha pienamente appoggiato l’iniziativa, ribadendo la necessità di “garantire l’indipendenza digitale europea dagli Usa“. Il deputato austriaco centrista Helmut Brandstätter, coordinatore del vertice, ha commentato l’incontro, tornando sul tema dell’impiego da parte di Strasburgo e Bruxelles di tecnologie americane. “Attualmente, il Parlamento Europeo utilizza software stranieri che possono essere disattivati, monitorati o utilizzati come arma politica da un giorno all’altro“, ha spiegato Brandstätter. “Questo non è solo scomodo, ma rappresenta anche una vulnerabilità strategica“. L’esponente de ‘La Nuova Austria e Forum Liberale‘ ha poi chiarito che non si tratta di una posizione “anti-americana”, ma “a favore della sovranità europea”. Immancabile la replica di Robin Koch, responsabile della comunicazione del colosso informatico. “Microsoft è orgogliosa di offrire la più ampia gamma di soluzioni di sovranità oggi disponibili sul mercato”, ha sottolineato Koch. “Continueremo a cercare nuovi modi per garantire al Parlamento Europeo e agli altri nostri clienti europei le opzioni e le garanzie di cui hanno bisogno per operare con fiducia”.
cybersecitalia.itNov 27, 2025extracted