Search/synology
Vendor

synology

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
photo station uploader
Connections
126 relationships
Synology ActiveProtect Manager 2.0 improves AI-driven security
Synology ActiveProtect Manager 2.0 improves AI-driven security Synology launched ActiveProtect Manager 2.0 (APM 2.0), the latest software update for its ActiveProtect data protection appliances. This release introduces expanded platform coverage, cross-platform recovery, and enhanced security, with future updates bringing AI-driven threat mitigation. “Managing fragmented backup infrastructure drives up costs and slows recovery. The ActiveProtect appliance unites purpose-built storage with powerful data management software into a single, predictable investment,” said Jia-Yu Liu, EVP of the Synology Data Protection Group. “APM 2.0 builds on that value, enabling organizations to safeguard their entire hybrid infrastructure through one centralized, scalable solution.” Expanded platform coverage APM 2.0 extends protection to Amazon EC2, Azure VM, Proxmox VE, Nutanix AHV, and Google Workspace. Cross-platform recovery allows workloads to be backed up and restored across different environments, supporting both disaster recovery and seamless workload migration. Backup destinations have also expanded. ActiveProtect Vault now supports a wider range of Synology NAS, while Azure Blob Storage joins the list of supported copy and tiering targets. Backups stored in Amazon S3 Storage or Azure Blob Storage can be restored directly into either Amazon EC2 and Azure VM as a Cloud DR strategy without routing through on-premises hardware, significantly reducing recovery times. AI-driven proactive resiliency ActiveProtect Manager 2.0 adds software-based storage encryption at the volume level to secure data at rest. Backup data and system configurations remain inaccessible in the event of drive theft or hardware loss. The upcoming APM 2.1 update will add AI/ML anomaly detection, tracking each backup version for shifts in change rate, file modifications, mass deletions, and entropy. Suspicious backup copies will be moved to quarantine for administrators to investigate, limiting the risk of backup contamination. The model learns from those outcomes to improve accuracy and reduce false positives. APM 2.1 will also scan backups for malware before restoration, using integrated third-party antivirus software such as Microsoft Defender, Bitdefender, and ESET. If malware is detected in the most recent backup, Auto Fallback restores the latest clean version instead. Availability ActiveProtect Manager 2.0 is available for all DP Series appliances.
helpnetsecurity.comSep 4, 2026extracted
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP , a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing. TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed  Shai-Hulud , which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen. Writing for Wired , journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers. “The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May . “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.” TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries. A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com. “TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote . “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.” In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM , an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies. In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub , after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware. MEET THE CYBERCATS Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals. “It is not a structured criminal crew with a single operator,” said Austin Larsen , a principal threat analyst with the Google Threat Intelligence Group . “It is a peer community of individually-skilled actors, with one clear center of gravity.” That center of gravity is George Prepakis , an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub . Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months. A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months. Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media. The Cybercats administrator listed at the top of the screenshot above — “ Boxturtle ” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle . This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group , Audi , Honda , Mercedes-Benz , Volvo and Toyota , as well as data allegedly taken from Snapchat and SportRadar . The data leak site for the extortion group or handle “xpl0itrs.” The Cybercats administrator “ SeesawSec ” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec , which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk , the data broker LexisNexis , and Avnet , a Fortune 500 distributor of electronic components. The data leak site of Fulcrum Security, a.k.a. Fulcrumsec. The Cybercats administrator “ @pcpcasper ” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia. At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning. The Cybercats member roster pictured above also features an administrator with the username “ T ,” which is short for the now-banned Twitter/X profile @pcpcats , the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia. By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off. WHO IS THE TEAMPCP LEADER? The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host , which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars. DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com. According to the cyber intelligence firm Intel 471 , Express registered on Breachforums using the email address [email protected] . Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa . On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency. The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP —  who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025. Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign . This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.” BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.” The identity threat protection company SpyCloud finds [email protected] shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found. KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com , and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson . Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025. Searching on “ joshuathomson39 ” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben , his father Ian , and his mom Cindy. That Facebook profile also says Josh and his family are originally from Pietermaritzburg , in KwaZulu-Natal, South Africa, but currently living in Cottesloe , a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au , thomson.org.au , and thomsonfamily.net.au . Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa. Constella finds a [email protected] registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports [email protected] frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including [email protected] and [email protected] . According to Intel 471, [email protected] was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15 . On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to [email protected]. A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org. SpyCloud reports 10.141.230.15 was used by the email address [email protected] on Raidforums and [email protected] on Nulled, and that the same IP was used by the email addresses [email protected], [email protected], and [email protected]. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420 , YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says [email protected] was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen. Epieos reports that [email protected] is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis . I’m a Perth creative who occasionally books rooms when visiting family and for photography.” Epieos also finds [email protected] registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development. “I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.” The Upwork profile for Ruben Thomson in Cottesloe, Australia. Epieos further discovered [email protected] is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that [email protected] was used to register a forum account named ChristmasSnow). This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia. Business reviews in Western Australia left by the Google account sheepstealing at gmail.com. The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson. Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions , Tensor Industries , and another entity ironically named OPSEC Express . Recall that Express was BulkDMT’s nickname on Breachforums. Australian companies connected to Ruben Thomson. Image: abr.business.gov.au. It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice. There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne , a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3 , a nickname that has been flagged by multiple security firms as an alias used by TeamPCP. The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io. INTERVIEW WITH ELLIS In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis]. Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene. “One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.” Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.” “Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.” Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it. “I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.” Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested. “If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.” It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.” “What kind,” @kernelstub inquired. “Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand. Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends. Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer. An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT. The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today. Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories. “They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.” Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap. “You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.” According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences. “They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.” In a recent blog post , Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards. In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature. Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years. “They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.” Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.
krebsonsecurity.comAug 27, 2026extracted
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform managed service providers and IT teams use to administer customer endpoints. After compromising an N-central server, the attackers used Take Control to reach managed endpoints and registered Cloudflare tunnels as services on the devices. The tunnels connect outbound to Cloudflare's edge, so they need no inbound firewall rule or open listening port. Running them as services lets them survive a reboot. N-able said the tunnels preserved access after the route through the N-central server was revoked. Nothing in the disclosure suggests Cloudflare was compromised; the attackers abused its tunneling service. Every N-central customer should be on 2026.3.1.7. Upgrading to 2026.3, N-able's initial instruction, is no longer sufficient. N-able's hotfix notice says hosted NCOD instances will be upgraded automatically on a schedule communicated directly to partners; self-hosted servers must be upgraded by the customer. Customers that find evidence of compromise must also hunt for and remove malicious tunnel services from managed endpoints, because upgrading N-central does not remove persistence installed on another machine. N-able began investigating on July 31 after an unusual volume of licensing errors from on-premises customers. It found that an attacker had remotely gained administrative access to servers running 2026.1 and earlier. N-able said it identified and contacted a limited number of affected customers but did not provide a figure. The first flaw, CVE-2026-18556, is titled "unauthenticated administrative account takeover" in N-able's own CVE record and classified as an authentication bypass through an alternate path or channel, or CWE-288. N-able assigned both CVEs and scored each 8.2 on CVSS 4.0. Neither record identifies the vulnerable endpoint or request sequence, and N-able has published no code-level root-cause detail. CVE-2026-18556 covers releases through 2026.1. N-able said it fixed that path in 2026.2, but later found an alternative way to exploit the same vulnerability that the earlier fix did not block. That finding became CVE-2026-18577 and expanded the affected range to builds before 2026.3.1.7. Finland's national cyber security centre said in an August 2 advisory that all versions available before the emergency hotfix were vulnerable. The Hacker News has reached out to N-able for clarification on the incident's scope and incomplete patch. This story will be updated with any response. N-able has now published six IP addresses seen in the attacks: 173[.]249[.]252[.]200 87[.]249[.]138[.]34 37[.]19[.]210[.]32 37[.]153[.]90[.]88 92[.]118[.]112[.]181 68[.]235[.]46[.]214 Huntress later identified the four addresses from N-able's initial list as Mullvad or NordVPN exit nodes. Huntress advised correlating any matches with N-central UI, network, and endpoint logs. N-able also told customers to look for svchost.exe in users' Documents folders, a service named Cloudflared, or traffic from the published IP addresses. It advised customers who find any of these indicators to contact support and engage their security teams. Huntress, in a rapid response published August 3, initially said it had seen exploitation at one organisation in its customer base and published three attacker domains: mousears.synology[.]me, wagoosh.direct.quickconnect[.]to, and who-ripped-one.direct.quickconnect[.]to. In an email to The Hacker News, Huntress clarified that the activity involved a self-hosted N-central instance within one partner account. The attackers accessed nine organisations under that account, reaching one endpoint in each. Based on the evidence available so far, Huntress said the post-compromise activity was limited to enumerating running processes on the endpoints before the attackers disconnected. The company is continuing to review the activity for other indicators of compromise and attacker tradecraft. Huntress said it did not observe the Cloudflare installation activity that N-able described in its original notification to affected customers. For signs of unauthorized Take Control activity, Huntress recommended checking ui_access_control.log and correlating it with C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz on Windows endpoints. Those logs also appear during legitimate Take Control use, so their presence alone is not proof of compromise. It also advised investigating sessions tied to apparent N-able support identities, such as [email protected]. N-able has not disclosed the number or identities of affected customers, how many downstream devices were reached, when exploitation began, who is behind it, or whether any data was taken.
thehackernews.comAug 3, 2026extracted
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems trusted the wrong instructions. Same soft spot throughout: trust placed one layer too early. Below is the full recap, since this is apparently what counted as a normal week. ⚡ Threat of the Week NetNut Residential Proxy Network Disrupted — Google, in collaboration with the U.S. Federal Bureau of Investigation (FBI), Lumen, and other partners, took action against the NetNut residential proxy network, also known as Popa, building upon its takedown of IPIDEA in January 2026. Google said it disabled Google accounts and associated Google services used by NetNut for malware command-and-control (C2) and updated Google Play Protect, in addition to disabling applications known to incorporate NetNut SDKs. The size of the network is estimated to be at least 2 million devices globally. "NetNut populates its botnet by distributing SDKs for devices commonly found in homes, such as smart TVs and streaming boxes," Google said, adding it "identified NetNut botnet plugin components for large-scale botnets such as BADBOX 2.0." The end goal is to leverage the route traffic through these devices, allowing bad actors to mask malicious activity. The devices are pre-installed with malware before purchase or because users unknowingly download applications containing hidden proxy code. Case Study: How 1Password Secured Canva's Path to 260M Users When Canva 5xed their headcount across 8 countries, they needed security that could scale as fast as their business. See how 1Password helped them onboard teams in minutes, eliminate secret sprawl, and keep engineering moving. Learn More ➝ 🔔 Top News WhatsApp Gets Usernames But Impersonation Concerns Are Raised — WhatsApp officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through usernames, as opposed to directly sharing their phone numbers. The feature is expected to be generally available later this year. The rollout marks a shift in how people identify one another on the messaging app. It has also drawn scrutiny in India, its largest market, over concerns it could be abused to impersonate public authorities, financial institutions, government departments, and other prominent figures. While Meta told TechCrunch it reserves usernames for public figures, government entities, and some of their variations so that only legitimate users can claim them, it's currently not clear how it decides which lookalike usernames get reserved and which don't. ChocoPoC RAT Targets Vulnerability Researchers with Fake PoC Exploit Repos — Security researchers on the lookout for Python-based proof-of-concept (PoC) repositories on GitHub claiming to exploit new CVEs are being tricked into executing malicious code that delivers ChocoPoC. While the PoC in itself looks clean, the actual malware sits inside a dependency named "skytext" pulled by the PoC. The malware is a full-featured trojan capable of harvesting passwords, cookies, autofill, and history from Chrome, Brave, Edge, and Firefox. It also captures text files, notes, local databases, shell history, network settings, and a list of running processes, as well as supports running arbitrary shell commands or Python code. 19-Year-Old Alleged Scattered Spider Suspect Extradited to the U.S. — Peter Stokes (aka Bouquet, Spencer, and Jordan), a 19-year-old man with dual U.S. and Estonian citizenship, was extradited from Finland to the U.S. to face criminal charges over his involvement in a criminal scheme in connection with the Scattered Spider hacking group. Finnish police arrested him in April 2026. Stokes and other Scattered Spider members are alleged to have breached an unspecified "luxury-jewelry retailer" in May 2025 and demanded an $8 million ransom in cryptocurrency. The company incurred at least $2 million in losses from business disruption, incident response, and recovery efforts. Stokes was involved in at least four Scattered Spider breaches, the Justice Department said. Stokes faces charges of fraud, conspiracy, and computer intrusion. Ousaban Banking Trojan Targets Spain and Portugal — A new Brazilian banking trojan called Ousaban has been observed using fake PDF documents containing a link to a malicious web page that scans the user's environment. "If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack," Fortinet said. "The final payload is an EXE file that is dropped onto the victim's computer and executed by the VBS script." Ousaban gets triggered when victims visit a banking site, at which point it captures screenshots and keystrokes, tampers with the clipboard, and enables remote control. AI-Generated Browser Ransomware Exploits Chromium File Access API — A new malware artifact generated using DeepSeek has constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the browser on Windows, Linux, macOS, and Android devices. The approach is limited to web browsers that expose the picker-based File System Access API. This includes Google Chrome and other Chromium-based browsers across Windows, macOS, ChromeOS, Linux, and Android. There is no evidence that the browser-native ransomware pattern has been abused in the wild. "What we are witnessing is a fundamental shift in how novel cyber attacks are born," Check Point said. "For the first time, we have evidence that an AI model can independently reason across legitimate platform features and surface a working attack technique that humans had only theorised about – without the attacker ever knowing the underlying API existed." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-48276, CVE-2026-48283, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48313, CVE-2026-48315 (Adobe ColdFusion), CVE-2026-48286 (Adobe Campaign Classic), CVE-2026-50548, CVE-2026-50549 (Cursor), CVE-2026-46242 aka Bad Epoll (Linux Kernel), CVE-2026-6682, CVE-2026-6687, CVE-2026-6688 (FatFs), CVE-2026-8037 (Progress Kemp LoadMaster), CVE-2026-28701, CVE-2026-33560, CVE-2026-31928 (Daktronics Controller Firmware), CVE-2026-41120 (Dell Wyse Management Suite), CVE-2026-41492 (Dgraph), CVE-2026-55047 (Anthropic Buffa), from CVE-2026-13774 through CVE-2026-13788 (Google Chrome), CVE-2026-48519, CVE-2026-48520, CVE-2026-7528, CVE-2026-7524 (Langflow), CVE-2026-3199 (Sonatype Nexus Repository), CVE-2026-12166, CVE-2026-12167, CVE-2026-12168 (Little Orbits GameFirst Anti-Cheat driver), CVE-2026-56141, CVE-2026-56142, CVE-2026-50242, CVE-2026-50242 (JetBrains), CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 (ClamAV), CVE-2026-20191 (Cisco Catalyst Center), CVE-2026-53917, CVE-2026-54475, CVE-2026-49877 (Apache ActiveMQ), CVE‑2026‑13050, CVE‑2026‑13053, CVE‑2026‑13054, CVE-2026-13079 (WatchGuard Fireware OS), CVE-2026-45504 (Microsoft Exchange Server), CVE-2026-14191 (WinRAR), CVE-2026-44024, CVE-2026-44025 (Fluentd), CVE-2026-55957, CVE-2026-55956 (Apache Tomcat), CVE-2026-13136, CVE-2025-15660 (Synology MailPlus Server), CVE-2026-22678, CVE-2026-49102, CVE-2026-49103, CVE-2026-42210, CVE-2026-56022 (Webmin), from CVE-2026-12044 through CVE-2026-12050 (pgAdmin), CVE-2025-66273, CVE-2025-66279, CVE-2026-22893 (QNAP QTS, QuTS hero, QuTS cloud, and QVP), CVE-2026-11310, CVE-2026-11999, CVE-2026-6679, CVE-2026-55958, CVE-2026-55960, CVE-2026-55961 (wolfSSL), CVE-2026-48611 (phpBB), and CVE-2026-20896 (Gitea). 🎥 Cybersecurity Webinars AI Attacks Are Moving Faster Than Your Defenses → AI is helping attackers write better lures, change tactics faster, and run campaigns at a scale many security teams are not built to handle. This webinar breaks down how AI-powered threats like Mythos gain access, move through environments, and expose the limits of traditional network-based defenses—then shows how teams can reduce attack surface, stop lateral movement, and contain risky behavior before it turns into a major incident. Your AI Agents Need a Kill Switch → AI agents can do more than make mistakes—they can expose credentials, bypass controls, and become a new attack surface inside the business. This webinar uses hands-on findings from OpenClaw testing to show where agentic AI breaks down, why guardrails are not enough, and how teams can reduce risk with identity-based governance, least-privilege access, short-lived secrets, logging, auditing, and visibility into shadow AI use. 📰 Around the Cyber World Indirect Prompt Injection Attacks Targets AI Agents for Typosquatting and Payment Scam — Threat actors are using indirect prompt injection (IPI) to hide instructions in websites, attempting to trick an AI agent into following the attacker’s instructions. "The observed campaigns combine SEO poisoning with CSS/HTML abuse to both manipulate search results and conceal prompt-style instructions that influence AI decision making," Zscaler said. "When AI agents misclassify malicious websites as legitimate, they increase the risk of context contamination and downstream Retrieval-Augmented Generation (RAG) poisoning." Dropping Elephant Delivers In-Memory RAT — The threat actor known as Dropping Elephant (aka Patchwork) has been observed using a China-themed energy-sector contract lure to deliver a heavily reworked, in-memory remote access trojan (RAT). "This campaign demonstrates advanced evasion techniques, including DLL side-loading with a legitimate Microsoft binary (Fondue.exe) and the use of 'Donut' shellcode to map the RAT directly into memory, effectively bypassing traditional disk-based security controls," Rapid7 said. "The revamped RAT significantly complicates detection by using control-flow flattening, runtime API reconstruction, and hardened C2 communications." The malware supports directory listing, file upload/download, screenshot capture, and command execution capabilities. Microsoft Updates SSPR to Require Registered Authentication Methods — Starting September 7, 2026, Microsoft said Entra self-service password reset will require users to have explicitly registered authentication methods for password reset verification, while explicitly disallowing directory-sourced contact information unless registered. "Currently, SSPR may allow users to verify their identity using contact information stored in directory attributes such as mobile phone, business phone, and alternate email, even if those values were never explicitly registered as authentication methods," Microsoft said. "To strengthen identity security, SSPR will require explicitly registered authentication methods for verification. This change is part of Microsoft’s Secure Future Initiative and ensures password reset verification is based on trusted, user-validated methods rather than directory-sourced attributes." The development comes as the Windows maker has introduced jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms, preventing Entra credentials from functioning on jailbroken/rooted devices. Scammers Exploit Trusted Brand Names to Drive Casino Traffic — Scam advertising campaigns are impersonating trusted brands to drive consumers to unrelated online gambling sites. "These campaigns utilize paid social ads, fake app store pages, and Progressive Web Apps to make users believe that well-known brands have launched 'official' casino or slot products," Netcraft said. "The scams begin with an ad on social media platforms such as Facebook, Instagram, and TikTok. The ad claims that a recognizable brand has launched '[Brand] Slots' or a similar gambling product. Upon interacting with the ad, the user is taken to a fake landing page designed to look like an official app store listing or branded game page. Instead of installing a real app, the user is prompted to add a Progressive Web App to their device, which opens an unrelated online casino through affiliate tracking links." PhishLumos as a Way to Counter Cloaking-Based Phishing Threats — As phishing continues to be a persistent threat in cybersecurity, researchers from Tokyo Metropolitan University and NTT Security Holdings have demonstrated PhishLumos to counter campaigns that evade automated scanners through cloaking and selective blocking techniques. "When content is missing, deceptive, or inaccessible, PhishLumos pivots to infrastructure evidence, including shared domains, IP addresses, certificates, and historical scan metadata," the researchers said. "It consolidates observations into a typed property graph knowledge base with a deterministic, idempotent merge operator and provenance for auditable investigations. A supervisor agent coordinates specialized agents and synthesis agents powered by large language models to profile campaigns and generate empirically validated detection rules for deployment in existing controls." CVE Explosion in the AI Era — With artificial intelligence (AI) and large language models (LLMs) accelerating vulnerability discovery, a new report from ProjectDiscovery has found that 30,550 CVEs have been published so far in 2026, a figure that's expected to eclipse 2025's 49,458 CVEs. Of these, 2,906 are rated critical, and 11,187 are rated high in severity. In contrast, a total of 30,361 CVEs were published in 2023. "The exploitable surface is doubling faster than defenders can absorb," ProjectDiscovery said. When the median time-to-exploit is days and the mean is negative, a 55-day critical-remediation cycle is not a process, it's an open door. If attackers are weaponizing bugs in minutes with AI, the response, finding them, proving they're real and handing developers a fix, has to run continuously and autonomously, not on a calendar." New ClickFix Campaign Uses Blockchain C2 — An active malware-as-a-service (MaaS) operation is abusing the Polygon (MATIC) blockchain as a resilient C2 configuration with a ClickFix lure. More than 130 compromised lure websites have been detected so far as part of the campaign. "Compromised websites are injected with a script named tracker.js, appearing as 'JokerStat Analytics Tracker,'" Palo Alto Networks Unit 42 said. "In addition to the clipboard injection, this script performs screenshot and victim-session telemetry exfiltration every 2 minutes." When a victim visits a compromised site, the injected JavaScript performs a blockchain lookup to fetch the C2 server URL. "After C2 resolution, tracker.js starts collecting victim telemetry, including pageview events, heartbeat and screenshots," Unit 42 said. "The same tracker.js then injects the clipboard content personalized per victim. The victim sees a fake CAPTCHA overlay and follows the instructions leading to a ClickFix attack." The attack culminates with the deployment of an infostealer written in Ruby. 2 Venezuela Nationals Sentenced in ATM Jackpotting Attacks — Two illegal aliens from Venezuela, Carlos Javier Padron, 36, and Arnoldo Cabrera Torrealba, 37, were sentenced to 78 months in prison in the U.S. for their involvement in ATM jackpotting activities. The two individuals pleaded guilty to one count of conspiracy to commit bank burglary and one count of computer fraud and intentional damage to a protected computer. The defendants built and deployed a variant of the Ploutus malware on ATMs across the country and used it to withdraw money without authorization. "The conspiracy relied on individuals, including Padron and Torrealba, to deploy the Ploutus malware onto ATMs in person," the U.S. Justice Department said. "Once installed and activated, the malware permitted the co-conspirators to issue commands to the cash dispensing module of the ATM in order to force unauthorized withdrawals of currency." Padron and Torrealba were also ordered to jointly pay $1.53 million in restitution. More than 90 other defendants have been charged over their roles in the operation. Bypassing Microsoft Entra Conditional Access Policies — NetSPI said it found a way to bypass Microsoft Entra Conditional Access Policies by abusing Nested App Authentication to return access tokens for the Microsoft Graph API. "It was possible to use certain Nested App Authentication (or BroCI) flows to bypass any Conditional Access policy," security researcher Thomas Byrne said. "This vulnerability served mainly as a persistence mechanism as it would have required a successful phishing attack to return an initial refresh token before the vulnerable authentication flows could be carried out." A fix for the issue has since been rolled out by Microsoft. Threat Actors Target Laravel Livewire Flaw — More than 6,100 applications have been compromised as part of a campaign targeting CVE-2025-54068, a critical unauthenticated RCE vulnerability in Laravel Livewire, to deliver a credential stealer by means of a shell script. The stealer harvests database-related configurations, Stripe secret keys, SMTP passwords, Google OAuth client secrets, JWT secrets, and AWS IAM credentials from .env files and exfiltrates them to a remote server. The campaign is assessed to have been underway for several months. "Recovery and analysis of the attacker's exfiltration infrastructure revealed credentials harvested from 6,167 distinct applications spanning dozens of countries and sectors, from e-commerce and healthcare to financial services, education, and government," Imperva said. "The attacker’s FTP server contained 1,851+ database dumps and 18+ email lists with over 26 million addresses, indicating the stolen credentials were being actively exploited." The activity has been attributed to an Indonesian-origin threat actor. Booking.com Partner Firms Targeted in TONResolver Campaign — Attackers are targeting employees of Booking.com partner companies in Japan using phishing emails that impersonate guest complaints and review requests to trick hotel staff into executing malicious files. The emails are sent using the notification functionality of a scheduling tool service, allowing them to bypass SPF, DKIM, and DMARC checks. The attacks led to the deployment of TONResolver, which abuses the Open Network (TON) blockchain platform as a dead drop resolver. "In this attack, a ZIP file was downloaded by accessing a hyperlink to a suspicious website, and the infection began when the user clicked a shortcut link file (LNK) disguised as a photo file within the ZIP archive," Trend Micro said. This triggers the execution of PowerShell that fetches and runs the JavaScript-based TONResolver malware using "node.exe," a core executable file for Node.js. The malware then connects to the C2 server obtained from the TON platform for additional attack execution and sends commands. Mamont Android Malware Dissected — An Android malware called Mamont is distributed via dropper apps masquerading as dating services to facilitate financial fraud. "The dropper and its embedded companion APK work in tandem to silently install, launch, and maintain control over the victim device while performing financial reconnaissance and awaiting attacker instructions," NCC Group said. A second variant of the malware has been found to serve phishing overlays inside Android WebView components at runtime, while also initiating phone calls, collecting installed applications, gathering device/network information, and manipulating system behavior to suppress notifications. "Additionally, it can execute commands dynamically based on input, indicating remote control functionality, and it reports execution results back through an internal handler or communication channel," security researcher Vamsi Pavuluri said. 2 Campaigns Deliver AsyncRAT — Phishing emails containing a Dropbox URL as well as macro-laced spreadsheets to distribute AsyncRAT malware. "When the recipient clicks on the link, a ZIP file is downloaded," Forcepoint said. "This file contains an Internet shortcut file in a .URL format. Opening this file leads to downloading multiple malware payloads in the background while the user is deceived by a legitimate-looking PDF opening. This file leads to a .lnk file, which then leads to a JavaScript file. This JS file links to a .BAT file, which hosts malicious content that ultimately delivers another ZIP file. This new ZIP file houses the Python script used to execute the AsyncRAT malware." The second campaign, detailed by LevelBlue, involves the use of generic emails targeting sales, procurement, and vendor management staff with a malicious spreadsheet that uses an embedded macro to download an HTA script, which then performs environment checks before delivering AsyncRAT or Remcos RAT. Clubfoot Wolf and Fluffy Wolf Targets Russia — BI.ZONE has disclosed cyber attacks mounted by an intrusion set it tracks as Clubfoot Wolf targeting a wide range of Russian sectors using spear-phishing emails to deliver NetSupport RAT to establish persistent remote access. A second threat cluster dubbed Fluffy Wolf has leveraged malicious email attachments and GitHub repository URLs to redirect recipients to ZIP archives that deliver PureLogs Stealer, PureRAT, and the Pay2Key ransomware. Also put to use in the attacks is a previously unreported C++ downloader called PowerLoader to fetch malicious PowerShell scripts from the C2 server over HTTP. In this attack chain, the loader is responsible for retrieving PureCrypter, which then launches the final payload. Multiple PhaaS Kits Spotted in the Wild — A number of phishing-as-a-service (PhaaS) toolkits have been identified: CodeStorm (which is a tenant-aware Microsoft 365 phishing kit), ARToken (a fully-featured PhaaS operator panel that shares overlaps with EvilTokens, a device code phishing toolkit), Console (for harvesting AWS console credentials), Mirage2FA (which uses short-lived HTML smuggling and obfuscated JavaScript-loaders to deliver fake Microsoft 365 login pages), and Bluekit (which uses browser-in-the-middle technique to load the legitimate login page inside an attacker-controlled browser, causing the victim to log into their accounts on the attacker's machine). At the same time, reports indicate that the Tycoon 2FA PhaaS service has resurfaced with new infrastructure and obfuscation layers following its law enforcement takedown back in March 2026. These developments also coincide with a surge in device code phishing attacks that exploit legitimate OAuth flows. Specifically, the attack tricks users into entering a device code that then issues active cookies and tokens directly to the attacker's device, bypassing multi-factor authentication (MFA). In tandem, Chinese-language phishing-as-a-service (PhaaS) communities are expanding in an area historically dominated by Russian-speaking cybercriminal groups. One such PhaaS service is the Darcula platform, linked to threat actor UNC5814, which has abandoned static phishing templates in favor of AI-powered page generators and browser automation tools, Loke Puppeteer, that can clone legitimate websites by replicating their HTML, CSS, JavaScript, and visual elements. Because each generated phishing page is unique, traditional signature-based detection methods are rendered ineffective. While PhaaS is at the core of these operations, these developers also typically offer numerous ancillary services, including the sale of personal and financial information. According to a report from Group-IB, data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. These include marketplaces like Exchange Market, Chang’An Sleepless Night, Aiqianjin, Yiqun Data, and Phoenix Overseas Resources. 🔧 Cybersecurity Tools T3MP3ST → It is an open-source offensive security framework that connects to an AI coding agent and uses it to run authorized security tests across web apps, CTF-style challenges, source code, and other targets. It provides a browser War Room and CLI for recon, exploit testing, and reporting, while its maintainers state it should only be used on systems the user owns or has written permission to test. NOX → It is an open-source Go-based tool for attack surface management, reconnaissance, and vulnerability scanning. It can run passive checks, quick probes, custom YAML workflows, or a full scan using 299 built-in modules across OSINT, subdomains, DNS, ports, web fingerprinting, and deeper vulnerability tests. Its maintainers warn that active scans make real network requests and should only be run against systems the user owns or has written permission to test. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Most of this week’s problems did not need a clever attacker so much as a useful opening. A trusted device, a trusted repo, a trusted reset path, a trusted browser feature. That word did a lot of damage. Patch what is yours. Question what looks too clean. And maybe stop assuming the boring parts are safe just because they look boring.
thehackernews.comJul 6, 2026extracted
In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
SecurityWeek’s cybersecurity news weekly roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Anonymous-linked hacker Aubrey Cottle jailed over Texas GOP cyberattack Aubrey Cottle, a Canadian hacker associated with the hacktivist group Anonymous, has been sentenced to 18 months in prison for his involvement in a cyberattack on the Texas Republican Party’s website in September 2021. Cottle, 39, of Oshawa, Ontario, pleaded guilty to defacing the website, exfiltrating data from a Texas GOP server, and publishing the data online. 14 million impacted by KDDI data breach Japanese telecoms provider KDDI has disclosed (PDF) a data breach likely impacting the email addresses and passwords of 14,22 million people. The incident affected five ISP operators, including BIGLOBE, Chubu Telecommunications C., JCOM Co., NIFTY Corporation, and STNet. Push Security targeted in poisoned tenant attack Three years after detailing the poisoned tenant attack, Push Security was targeted using the technique via OpenAI’s organization invitation feature. Multiple employees received an OpenAI invitation to join Push Security Inc. After they would join the tenant, the attacker could spy on their activities or target them with further social engineering. Rust-based PamStealer targeting macOS Jamf has detailed PamStealer, an information stealer targeting macOS that validates the harvested credentials via Pluggable Authentication Modules (PAM) before using them. The malware is distributed as a compiled AppleScript file impersonating the open source clipboard manager Maccy. Russian hackers behind the 2025 Jaguar Land Rover hack The cyberattack that severely disrupted Jaguar Land Rover’s operations in September 2025 was mounted by Russian hackers, The New York Times says. Microsoft reportedly notified the car manufacturer about the hacking group, with Mandiant, Palo Alto Networks, and US and UK law enforcement agencies also involved in the investigation. Pegasus spyware targeted a European Parliament member investigating it Former member of the European Parliament Stelios Kouloglou was hacked with NSO Group’s Pegasus spyware while he was investigating Pegasus abuse cases, as part of the PEGA committee, Citizen Lab discovered. The targeting has not been attributed to a specific government, and there is no evidence that the Greek Government was involved. Researcher drops dozens of zero-days in open source projects A researcher known as Bikini has published proof-of-concept (PoC) code targeting dozens of zero-day vulnerabilities in multiple open source projects, including FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, OpenVPN, and VLC. Nine of the security defects have been assigned a CVE identifier. The issues, the researcher says, were surfaced via LLM fuzzing. Pro-Russia influence operations are shifting Four years into Russia’s invasion of Ukraine, pro-Russia influence operations are shifting from their single focus on Ukraine to pre-war objectives, Google says. Covert pro-Russia influence operations are targeting the US, European Union members, NATO, Russia’s neighbors, the Middle East and Africa, and internal entities. They focus on global events, elections, the war in Ukraine, and emerging geopolitical developments and events, and are increasingly relying on generative AI. Venezuelans sentenced in the US over ATM jackpotting Two illegal aliens from Venezuela, Carlos Javier Padron, 36, and Arnoldo Cabrera Torrealba, 37, have been sentenced to 78 months in prison in the US for their involvement in ATM jackpotting activities. As part of a sophisticated criminal group, they built and deployed a variant of the Ploutus malware on ATMs across the US and used it to withdraw money without authorization. They were also ordered to jointly pay $1.5 million in restitution. 96 other defendants have been charged over their roles in the operation. Cisco and Synology patches Cisco has released fixes for seven ClamAV vulnerabilities impacting Secure Endpoint Connector for Windows, Linux, and macOS, and Secure Endpoint Private Cloud, and for one flaw in Catalyst Center. Synology resolved three security defects in MailPlus Server, including two critical bugs that could allow attackers to read or write arbitrary files and cause DoS conditions.
securityweek.comJul 3, 2026extracted
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cleanup waiting. Here’s the full Monday recap. ⚡ Threat of the Week New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — Cybersecurity researchers detailed a new variant of the Dirty Frag Linux kernel flaw. Called DirtyClone (aka CVE-2026-43503), it allows local users to gain root privileges via cloned packets. The exploit works successfully on Debian, Ubuntu, and Fedora systems with default namespace configurations. "Any local user on a server or device running a vulnerable kernel who holds or can acquire the CAP_NET_ADMIN capability (frequently obtainable via unprivileged user namespaces) [is exploitable]," JFrog said. "This poses the highest risk to multi-tenant cloud environments, Kubernetes clusters, and containerized workloads where user namespaces are enabled, or privileged containers are deployed." Building Securely with AI: Takeaways from Chainguard Innovation Week Reactive network operations slow teams down and increase business risk. Join Tines and Netskope to discover a practical five-step framework for improving visibility, accelerating response, and creating secure, reliable operations across modern hybrid environments. Explore Innovation Week ➝ 🔔 Top News Critical PTC Windchill PDMlink and PTC FlexPLM Flaw Exploited — A critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software has come under active exploitation in the wild to deploy JSP web shells on susceptible systems. The vulnerability, tracked as CVE-2026-12569, is a case of improper input validation that could allow an attacker to execute arbitrary code by sending a malicious request to the network. Patches for the vulnerability have been released. OpenAI Previews GPT-5.6 Sol, Terra, and Luna — OpenAI officially unveiled GPT-5.6 Sol, Terra, and Luna, with Sol described as the most capable model yet for cybersecurity. The models are being released in a staggered manner with approval from the U.S. government. The release came days after the company released an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative and launched a new project called Patch the Planet in collaboration with Trail of Bits to help secure open-source projects. OpenAI has also warned about the dual-use nature of the technology, acknowledging that the same capability that helps a red teamer find a zero-day can also assist a bad actor in exploiting one, and that it will prioritize patching jailbreak techniques against the model. In addition, it has framed the effort as getting the tools in the hands of more defenders before attackers gain the same edge. Much of the concern surrounding the frontier models stems from the fact that artificial intelligence can now identify existing bugs within codebases and work towards creating exploits for them. While the automation of cybercrime is not new, these tools undoubtedly have the potential to further lower the barrier to entry for bad actors. New Gaslight macOS Malware Discovered — A newly discovered macOS malware dubbed Gaslight is designed to confuse AI-assisted malware analysis tools through embedded prompt injection strings and fake debugging data within the executable. With cybersecurity researchers using AI-powered tools to assist with malware analysis and reverse engineering, the malware attempts to gaslight such tools into thinking there is some issue, potentially causing them to abort, truncate, or refuse an analysis of the artifact. Gaslight has been attributed with high confidence to a North Korean-linked threat actor. The malware itself is a Rust binary with backdoor and information-stealing functionality, enabling the operator to gain a persistent foothold over the infected host. The findings highlight how threat actors are experimenting with anti-analysis methods designed specifically to bypass AI-assisted security platforms. Turla Uses STOCKSTAY Backdoor in Ukraine Attacks — The Russian state-sponsored threat actor known as Turla has leveraged a previously undocumented .NET backdoor called STOCKSTAY in attacks targeting government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. STOCKSTAY shares significant code and functional overlaps with Kazuar, a staple implant put to use by the adversary since 2017. Suspected development activity of malware dates back to December 2022. Amadey, StealC Malware Operations Disrupted in Operation Endgame — A coordinated law enforcement operation, in partnership with private sector companies, dismantled criminal infrastructure powering Amadey and StealC. According to Europol, the operation led to the disruption of 326 servers and 142 domains, the identification of more than €41 million ($47 million) in cryptocurrency linked to criminal activity, and the recovery of approximately 27 million credentials stolen from over 385k compromised systems. Amadey and StealC are sold to cybercriminals under a malware-as-a-service (MaaS) model. Microsoft said criminals use Amadey to gain an initial foothold on victim devices to deploy additional malware, such as StealC, which then steals credentials, cryptocurrency wallets, and other sensitive information that can later be sold or leveraged in follow-on attacks. The two malware families were linked to more than 140,000 infected devices during the first two weeks of May 2026 alone. That said, no arrests were announced as part of the operation. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-47729 aka Squidbleed (Squid), CVE-2026-12957 (Amazon Q Developer), CVE-2026-12569 (PTC Windchill PDMlink and PTC FlexPLM), CVE-2026-43503 aka DirtyClone, CVE-2026-46331 aka pedit COW (Linux Kernel), CVE-2026-30040, CVE-2026-30041 (FastStone Image Viewer), CVE-2026-45585 (Microsoft WinRE), CVE-2026-8461 aka PixelSmash (FFmpeg), CVE-2026-55200 (libssh2), CVE‑2026‑20971 (Samsung KNOX kernel), CVE-2026-10086, CVE-2026-10712, CVE-2026-12053 (GitLab CE and EE), CVE-2026-13028, CVE-2026-13032, CVE-2026-13033, CVE-2026-13038 (Google Chrome), CVE-2026-53605 (Reachy Mini Wireless image), CVE-2026-13136, CVE-2025-15660, CVE-2026-13135 (Synology MailPlus Server), CVE-2026-11374 (ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus and ADAudit Plus), and a critical Infoblox NIOS privilege escalation vulnerability (no CVE). 🎥 Cybersecurity Webinars Stop AI-Driven Cyberattacks Before They Stop Your Business → Hackers are now using AI to launch cyberattacks at machine speed. If your defenses are built for human-speed threats, you are at risk. Join this webinar to get a step-by-step blueprint to fight back. Learn exactly how to block AI-driven attacks and protect your company before a crisis hits. When AI Goes Rogue: How to Secure the New Cyber Attack Surface → As companies rush to adopt AI, hackers are turning these tools into a massive liability by hijacking AI agents and leaking trade secrets. Join this urgent webinar to see exactly how attackers weaponize AI against businesses. You'll get a practical blueprint to lock down your setups, fix risky configurations, and stop your own tech from going rogue. Building at Machine Speed: How to Secure AI Software Delivery → AI tools are generating code faster than security teams can review it, introducing hidden risks into software pipelines. Join this webinar to learn how to catch vulnerabilities and govern AI risk without slowing down development. You'll get a practical roadmap to protect your software supply chain and scale AI engineering safely. 📰 Around the Cyber World China's New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Discovery — The Wall Street Journal reported that a new model released by China's Zhipu AI, GLM-5.2, matches the performance of Anthropic Mythos when it comes to finding vulnerabilities, narrowing the gap between top U.S. models and those developed by Chinese companies. The ability of AI systems to autonomously find security defects in software has created new urgency to efforts that entail the use of models to quickly close them before they can be exploited by bad actors. There are also worries that these models, in the wrong hands, can become potential enablers of cyber warfare. The Trump administration has called for the creation of a framework that grants the federal government the ability to evaluate AI models' capabilities and determine which qualify as "covered frontier models," a designation for AI systems with advanced cyber capabilities. Indirect Prompt Injection in Agentic Coding Tools — Mozilla's Zero Day Investigative Network (0DIN) characterized indirect prompt injection as a "very real and serious attack vector that can result in catastrophic damage, much of which will be irreversible." In the case of agentic IDEs and coding agents, they can request access to various tools, which, once approved, can pave the way for code execution, file system operations, and network calls. Specifically, an attacker can obtain code execution using a seemingly harmless repository by chaining trusted setup instructions, routine error handling, and automated agent behavior. The attacker-controlled repository does not even have to contain any malicious code. Instead, it's fetched at runtime from a DNS TXT record by framing it as an essential step during the installation phase when a developer copies the repository link and instructs the agent to get it running. "In short, agentic coding tools have access to everything they need for this: private data, including environment variables, credentials, API keys, and local configuration files," 0DIN said. "Untrusted content, such as repositories, documentation, and error messages from recently installed packages, can inject malicious models to steal this data." New KuinaExtractor Rust Infostealer Spotted — A new Rust-based information stealer called KuinaExtractor comes fitted with capabilities to harvest web browser data, crypto wallets and credentials for services such as Roblox, Steam and Discord. Said to be in active development since December 2025, the stealer also includes a Chrome app-bound encryption (ABE) bypass. In parallel, the malware developer worked on two short-lived projects known as KuinaCookieExtractor and Zenith C2 before they were abandoned. KuinaCookieExtractor goes beyond browser cookies to include Roblox and Steam sessions, Minecraft and FileZilla logins, Telegram tdata and Discord tokens, and exfiltrates over a Discord webhook rather than Telegram. New LokiBot Campaign Surfaces After a Hiatus — A new email phishing campaign has been observed delivering LokiBot via a JavaScript attachment. Once launched, the script triggers the execution of a PowerShell loader that runs a .NET injector payload that deploys the LokiBot malware. LokiBot is capable of harvesting credentials from password managers like 1Password, Enpass, and KeePass, and contacts an external server to receive and execute commands. Phishing Campaign Drops Malicious Chrome Extension — Invoice-themed email phishing lures written in Italian are being used to launch JavaScript attachments masquerading as PDF documents. "The most interesting part of this infection was not the initial JavaScript. The malware installed a malicious Google Chrome extension and paired it with a Native Messaging Host," D3 Lab said. "This combination allowed code running inside Chrome to request PowerShell commands on the Windows system." Time as an Attack Surface — New research from NCC Group has argued the need for treating time as a "first‑class attack surface," stating clock drift, time synchronisation failures, and deliberate oscillator manipulation can be exploited to undermine cryptography, authentication, industrial automation, and safety systems. "The risk is amplified by broader technological trends," NCC Group's Andy Davis said. "Cloud computing, containerisation, and virtual machines abstract time away from physical hardware, placing it under the control of hypervisors and orchestration layers. At the same time, Industrial Control Systems, IoT devices, and safety-critical platforms increasingly rely on low‑cost oscillators and commodity components that are vulnerable to environmental influence and physical manipulation. Systems that once relied on isolated, deterministic timing sources are now interconnected, synchronised, and exposed." Threat actors Exploit Xiongmai DVR Flaw to Deliver Proxy SDK — Threat actors have been exploiting CVE-2024-3765, a vulnerability in Xiongmai DVR, to deploy commercial residential proxy SDKs using a Mirai botnet-derived HTTP downloader. "All DDoS and scanning capability has been stripped," the Nokia Deepfield Emergency Response Team (ERT) said. "What remains is a minimal HTTP client and an embedded userspace ELF loader – Mirai reduced to a delivery truck." The main stager installed following a successful compromise deploys a proxy binary called PacketSDK, which is part of the IPIDEA residential proxy network disrupted by Google earlier this year. The stager also contains a remote code execution backdoor that polls an external server for updates every 2 minutes. Nation-State Targeting of Water Systems — DomainTools warned that water and wastewater infrastructure have become strategic pressure points for state and state-aligned actors from China, Iran, and Russia. "The combination of chronic underinvestment and weak baseline operational technology (OT) security makes many of these critical systems easy to compromise," the company said. "Such intrusions can have both physical and psychological impact, and disruptions often affect civilian life, public health, and trust in government." Anthropic Accuses Alibaba of Obtaining Illicit Access to Claude — Anthropic has accused the Chinese company Alibaba of what it described as the "largest campaign to illicitly extract Claude's capabilities." The attacks occurred between April 22 and June 5, 2026, when "operators affiliated with Alibaba and Alibaba Qwen, Alibaba's AI lab," allegedly generated "more than 28.8 million exchanges with Claude through almost 25,000 fraudulent accounts," per Anthropic. The distillation campaign targeted its capabilities, such as agentic reasoning, software engineering, and long-horizon tasks, while evading detection using obfuscation techniques and proxy networks. Linux Foundation Unveils Akrites and OSERA — The Linux Foundation has announced Akrites as a coordinated effort to address and disclose vulnerabilities in critical open-source software as AI accelerates both the scale and speed of vulnerability discovery. "The initiative provides a single, trusted place to coordinate, remediate, and disclose, with a shared SIRT [Security Incident Response Team] serving as a predictable partner for maintainers rather than a flood of uncoordinated reports," the foundation said. The initiative also plans to work with critical infrastructure operators to help deploy fixes before in-the-wild exploitation. The Linux Foundation has also announced its intent to form an Open Source Enterprise Resiliency Alliance (OSERA) that aims to strengthen the open-source components that underpin the financial services sector through a vendor-neutral, upstream-aware approach. "OSERA complements the recently announced Akrites, the cross-industry effort enabling coordinated disclosure and upstreaming," the foundation said. "As financial-services downstream complement to Akrites, OSERA will collaborate with Akrites in the upstreaming process and, together with the Open Source Security Foundation, to represent the voice of the industry in defining remediation standards." Microsoft Extends Windows 10 Consumer Extended Security Updates by a Year — Microsoft quietly extended the Extended Security Updates (ESU) program for Windows 10 consumers by a year, letting eligible users get updates through October 12, 2027. To enroll in the consumer Windows 10 ESU program, devices need to be running Windows 10, version 22H2 Home, Professional, Pro Education, or Workstations edition and cannot be offered for devices in kiosk mode or those that are joined to an Active Directory domain or Microsoft Entra and/or enrolled in a Mobile Device Management (MDM) solution. Microsoft's Secure Boot Certificates Have Expired — In related Microsoft news, the certificates that manage UEFI Secure Boot trust – namely, Microsoft Corporation KEK CA 2011, Microsoft UEFI CA 2011, and Microsoft UEFI CA 2011 -- expired on June 24 and 27 2026. A third certificate, Microsoft Windows Production PCA 2011, will expire on October 19, 2026. "Many Windows PCs manufactured since 2024 already have the updated 2023 certificates," Microsoft said. "For the remaining devices, Microsoft is delivering new Secure Boot certificates through Windows monthly updates, with partner original equipment manufacturers (OEMs) making firmware updates available to help ensure compatibility." Google Cloud has also released guidance on how to update Compute Engine Shielded VM instances to trust the updated Microsoft Secure Boot certificates for UEFI Secure Boot. To apply Secure Boot certificate updates for Linux on Azure virtual machines, it's recommended to follow the actions outlined by Microsoft here. Separately, Linux users are advised to update their shims to the latest versions signed by the new key. It's important to note that devices that haven't received the newer 2023 certificates will continue to function normally, and standard Windows updates will continue to install. However, these devices will no longer receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot-level vulnerabilities. Fake OpenAI Organization Invites Used in New Poisoned Tenant Campaign — Phishing emails are being sent from threat actor-controlled ChatGPT tenants, inviting recipients to join an organization with the likely goal of harvesting sensitive information shared in the AI chatbot. "The emails came from OpenAI's legitimate notification address ([email protected]), passed all standard email authentication checks, and referenced our company by name," Push Security said. "They looked exactly like a routine organizational invitation because, technically, they were one." The development comes as threat actors are abusing AI chatbot chat sharing functionality to distribute pages containing malicious instructions, turning them into malware delivery platforms. "The attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable," Push Security noted. The activity has been codenamed LLMShare. 🔧 Cybersecurity Tools Sulla → It is an open-source security tool by Praetorian that scans internal network SMB file shares to find exposed credentials and sensitive data. Operating as a fast, low-noise static binary, it maps Active Directory environments and uses multi-layered filtering with the Titus engine to perform in-memory analysis for cloud keys, passwords, and tokens. It outputs structured, real-time results to help security teams identify and remediate internal data exposure before it can be exploited. Karna → It is a Web Application Firewall (WAF) module specifically engineered for the Kong Gateway to provide modern, scalable security for web applications. By integrating directly into the Kong ecosystem, it allows organizations to enforce fine-grained security policies and filter malicious traffic at the gateway layer, ensuring that protection is applied consistently across distributed services without adding significant latency. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion This week, keep it simple. Break the small thing, find the forgotten access, wait for someone to say they meant to patch it. No genius required. Just old mistakes with fresh damage. Shut the door. Check the locks.
thehackernews.comJun 29, 2026extracted
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone watching a network link. The encryption covers the message inside each packet. The packet still carries plaintext headers, and those values mark a flow as DNS. Agent Beacon: Open-source telemetry layer for AI agents AI coding agents such as Claude Code, Codex CLI, Cursor, and Claude Cowork run on developer laptops, CI jobs, cloud environments, where they edit files, run commands, and call outside tools. Beacon, an open-source project from Asymptote Labs, configures telemetry for those runtimes and writes a normalized record of what each agent does across local, CI, and cloud-agent surfaces. Who pays when you gate cyber-capable AI models? In this interview with Help Net Security, Jaya Baloo, COO & CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down for security teams who depend on the same capabilities for defense. A $1,400 experiment in AI security auditing outperformed OpenAI’s Codex Security A research team has built a system that teaches AI agents to hunt for software bugs by writing the audit method down as plain text. The system, called EVOHUNT, keeps the underlying AI model fixed and improves only an external “playbook” that tells the agent how to work. GTA 6 early access offers are taking gamers’ crypto Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early access for a few hundred dollars in cryptocurrency, ask buyers to enter a payment code, and claim the game will then unlock. Praxen: Open-source AI agent behavior verification Praxen is an open-source tool with a simple job: it checks whether an AI agent does what it claims to do. The tool takes an agent’s declared policy, looks at how the agent operates, and points out every spot where the two drift apart. Where IT meets OT and railway cybersecurity gets harder In this interview with Help Net Security, Jorge Aldegunde, Global Head of Railway Services at DNV, talks through what happens when old operational technology meets newer IT in monorail systems. He explains why open networks widened the attack surface, how teams decide whether to patch a signalling flaw without stopping trains, and who carries the liability. Scoring AI hackers when there is no answer key AI models are solving an increasing number of offensive cybersecurity benchmarks, making those tests less useful for evaluating the most advanced systems. Many rely on vulnerabilities that have already been publicly documented, allowing models to draw on existing knowledge. FrontierCyber, a benchmark from AI security lab Irregular, takes a different approach. It places models on real systems and measures how far they progress toward a security objective. The uptime questions every engineering leader should ask this week In this interview with Help Net Security, Mattias Geniar, CTO at Oh Dear, explains why most outages start quietly, as creeping latency or a slow rise in errors. He argues teams alert on the wrong things: absolute numbers instead of changes, isolated endpoints instead of real user outcomes. Healthcare leaders see a fatal cyber incident as inevitable Healthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside company a path into the practice, and any one of them can break. According to Omega Systems’ 2026 Healthcare IT Landscape Report, the large majority of practices dealt with at least one operational disruption that traced back to a vendor or a vendor’s own supplier. Two CEOs on why security and AI readiness belong together SuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time and context lost to tool-switching, lowers costs against multi-vendor setups, and helps close the gap between average MSP margins of 8% and the 18% top performers reach. What the Fortibleed campaign means for organizations running FortiGate firewalls A massive credential-harvesting campaign targeting FortiGate firewalls has exposed thousands of organizations to potential network compromise, and a trove of attacker tools, scripts, and credentials left inadvertently exposed on a server has given researchers an unusually detailed look at how the operation worked. Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. Law enforcement hits StealC and Amadey malware networks Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. Mystery hackers use novel SharkLoader dropper against governments, software devs Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. Synology issues critical fix for MailPlus Server vulnerabilities Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. Details about the vulnerabilities are still under wraps. Product showcase: How to evaluate AI SOC platforms and where Prophet AI leads The agentic SOC market is crowded with vendors promising to automate alert triage, investigation, and response. The challenge is separating measurable operational gains from marketing claims. Prophet Security is an agentic AI SOC platform that autonomously triages, investigates, and responds to security alerts. It also helps strengthen detection and response programs by identifying tuning opportunities, uncovering detection gaps, and enabling natural-language threat hunting. 23 ClawHub plugins squatting official scopes expose AI registry security gaps In this Help Net Security video, Ax Sharma, Head of Research at Manifold Security, breaks down how 23 code-executing plugins ended up under ClawHub’s official @openclaw and @clawhub scopes while owned by unrelated accounts, why an official-looking scope is a supply chain risk even when the code isn’t malicious, and what the registry changed after the disclosure. What your next cyber insurance renewal will demand In this Help Net Security video, Michael Loewy, co-founder, Tide Foundation, explains how cyber insurance is rewriting security programs at renewal time. Hundreds of AI-powered iOS apps found exposing credentials Mobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to those services remains a challenge. Researchers from Wake Forest University analyzed 444 iOS applications with LLM features and found 282 that exposed exploitable credentials or backend access mechanisms. Free, no-signup World Cup streams serve scams instead of football Researchers at Malwarebytes identified dozens of websites claiming to offer free access to FIFA World Cup matches. Instead of streaming games, the sites directed visitors through a chain of advertising pages designed to generate revenue for their operators. Phishing hides in routine Microsoft 365 workflows Attackers are abusing Outlook Groups and Microsoft 365 collaboration features to make phishing campaigns appear routine, according to Fortra. The attack begins when a target is added to or invited into an attacker-controlled Microsoft 365 Group. The group’s name, description, or welcome message is designed to create urgency, often using themes such as payroll updates, contract renewals, supplier requests, or mandatory training notices. Two Scattered Spider hackers plead guilty over Transport for London cyberattack Two members of the notorious hacker group Scattered Spider have pleaded guilty to charges related to a 2024 cyberattack on Transport for London (TfL) that resulted in £29 million in loss and recovery costs. Using Reddit to manipulate AI search results is surprisingly easy A Reddit comment that takes only a few seconds to write can end up influencing the answers generated by AI research tools. A Cornell Tech study found that a short snippet of user-generated text, sometimes as little as 13 words, was enough to affect the output of deep-research agents, AI systems that search the web, gather information from multiple sources, and generate reports with citations. LastPass customer data exposed through Klue supply chain attack LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. Phishing attack on healthcare firm Xsolis impacts 1.4 million people Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. Algerian national accused of running cybercrime marketplaces extradited to US An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. WhatsApp will warn users before they message a potential scammer WhatsApp is rolling out a warning screen on Android and iOS that appears before users open chats with unfamiliar phone numbers. Meta hopes that this new feature will help users avoid scammers. Hacker gets 18 months for attack that compromised 60,000 betting accounts A 21-year-old man known online as “Snoopy” was sentenced to 18 months in prison for his role in a scheme that hacked user accounts on a fantasy sports and betting website and sold access to them, causing hundreds of thousands of dollars in losses. Stealthy new backdoor surfaces in attacks on multiple sectors A relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec. A privacy-first take on local malware analysis Submitting a suspicious file to VirusTotal or MalwareBazaar uploads a copy to a searchable public repository. While these platforms help analysts quickly identify malicious files, they also allow threat actors to see when their tools have been detected by monitoring for matching hashes. In targeted attacks, uploaded samples may also contain sensitive victim data, exposing it to third-party systems. Burnyard, a research project from The Ohio State University takes aim at this condition. It runs suspicious binaries on the analyst’s own hardware and keeps each sample local for the duration of the analysis. Microsoft gives Windows 10 users an unexpected extra year of free security updates Microsoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. SIM-swapping gang busted in international police operation Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering. Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. The systemd 261 release brings a software TPM, new OS installer Linux distributions that ship systemd as their init system now have a new version to track. The systemd 261 update adds a cloud metadata subsystem, carries process state through kexec reboots, and continues a long-running effort to load external libraries on demand. Product showcase: Avira Security for iOS blends security, privacy, and device optimization Avira Mobile Security for iOS combines security, privacy, and device optimization tools in a single application. The app is also available for Android, macOS, and Windows devices. Only 7% of companies are ready for the AI agents they deployed Most organizations now run or pilot AI agents that operate on company data with limited human direction at each step, a share that reaches 88% in Veeam Software’s Data and AI Trust Gap report. The systems that are supposed to keep an eye on them have not caught up. Residential proxy SDKs are hiding in LG and Samsung smart TV apps Smart TVs in living rooms run small apps that show fish tanks, clocks, solitaire games, and slideshows of puppies. A share of those apps can also send other people’s internet traffic out through the home connection. Spur Intelligence scanned 6,038 apps across LG webOS and Samsung Tizen and found 2,058 that contain residential proxy software. OpenAI wants AI to fix vulnerabilities, not just find them OpenAI expanded Daybreak, its cybersecurity initiative that combines AI models, Codex Security, security researchers, maintainers, industry partners, and access controls to support vulnerability discovery and remediation. Organizations can use the initiative to identify, validate, and fix software vulnerabilities, while developers, maintainers, and security teams can use its tools to strengthen defensive security capabilities. Security testing was built for a slower world Software teams are pushing code into production faster than security testing can keep up. AI is accelerating development cycles and adding pressure to security programs that rely on periodic validation and manual penetration testing. The 2026 State of AI Security Testing report from Aikido Security found that 76% of organizations have had to stop, restrict, or roll back AI-driven behavior in the past 12 months. Google Workspace expands password reset alerts to all admins Google’s Alert Center, a dashboard in the Google Admin console that displays security and administrative alerts and helps administrators identify, investigate, and respond to issues affecting their organization, is expanding the “Super Admin password reset” alert into the “Admin password reset” alert. The feature is rolling out gradually and will be available to all Google Workspace customers. Anthropic’s Claude Tag gives AI agents independent identities Anthropic introduced an agent identity model for Claude Tag, its AI assistant designed for team collaboration in shared workspaces. The model gives Claude its own identity, permissions, and tool access, configured by administrators and tied to a workspace or channel. Most teams will ship AI-written infrastructure code with little review AI-assisted development has settled into everyday practice across software organizations, and developers using it move from idea to working code in hours. That code does not stay with the developers who prompt it. It flows downstream to the DevOps and platform teams who deploy and maintain it, and those teams are not getting the same speed boost. Best practices for AI in open-source work Free and open source software developers us AI coding assistants such as Claude Code, Copilot CLI, Antigravity, and OpenCode in their daily work. The Software Freedom Conservancy responded to that trend with a set of recommendations for contributors who use these tools, which it groups under the label LLM-gen-AI, meaning generative AI systems backed by LLMs. LLM security advice looks solid until you check the hard cases Plenty of people now type their security worries straight into a chatbot. A hacked account, a suspicious email, a stalker who might be tracking a phone, all of it lands in the same window someone would use to ask about dinner. A benchmark called HelpBench tests how well chatbots handle those moments, and the results give security professionals something to watch in what their users are being told. Google Wallet adds TSA Touchless ID for faster airport screening Google Wallet has joined the Transportation Security Administration’s (TSA) PreCheck Touchless ID program, allowing travelers to pass through security checkpoints using the TSA’s facial comparison technology. The system verifies identity by matching a live photo taken at a checkpoint with identity and flight information, reducing the need to present a physical ID. Modelplane: Open-source control plane for AI inference Organizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have built this coordination layer by hand, one operator at a time. Upbound, the company behind the Crossplane project, released Modelplane, an open-source control plane that manages fleet-wide coordination for AI inference. Ransomware gangs find Europe’s weakest link in third-party suppliers Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 European Cyber Risk Report. Critical open-source projects get a new security framework Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors, AI companies, and open source projects to support the remediation and disclosure of vulnerabilities affecting widely used open source software. Cybersecurity jobs available right now: June 24, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the month: June 2026 Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI.
helpnetsecurity.comJun 28, 2026extracted
Synology issues critical fix for MailPlus Server vulnerabilities
Synology issues critical fix for MailPlus Server vulnerabilities Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or write arbitrary files and conduct denial-of-service (DoS) attacks CVE-2026-13135, caused by improper restriction of communication channel to intended endpoints, may allow remote attackers to access internal services CVE-2025-15660, arising from the use of a cryptographically weak pseudo-random number generator, may allow adjacent attackers to read or write arbitrary files and conduct DoS attacks. Details about the vulnerabilities are still under wraps. Users running MailPlus Server on NAS devices with DiskStation Manager v7.3, 7.2.2 or 7.2.1 are advised users to upgrade to the recently released 4.0.1-31663 version of the software, as there is no available mitigation for the fixed issues. Over 2,100 deployments exposed to the internet Aside from technically inclined users who own a Synology NAS and want to run their own mail server, MailPlus Server is also used by small-to-medium businesses that want self-host email on their on-premises hardware – either for privacy, cost control, or compliance reasons. Bitsight’s Groma Explorer scanning engine “sees” 2,100+ internet-facing Synology Mailplus Server deployments, predominantly in Germany, Asia (Korea, China, Taiwan), and the US. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 26, 2026extracted
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke sniffers on compromised firewalls. "Once deployed, these sniffers capture cleartext and hashed credentials from traffic passing through compromised devices," SOCRadar said [PDF] in a fresh report. "The actors then crack, validate, and reuse the credentials against Active Directory domains and other exposed services." Central to the operation is a Golang-based tool called FortigateSniffer that takes advantage of the FortiOS built-in diagnostic command -diagnose sniffer packet to passively capture authentication traffic from the infected appliances. Appearing in both Windows and Unix versions, the tool is designed to monitor traffic across 24 protocols, parse authentication data, and extract the credentials. It's suspected that the threat actors may have sought the help of an open-source, AI-native offensive security platform dubbed CyberStrike to assist with some "parts of the workflow." Interestingly, another open-source framework called CyberStrikeAI was put to use in connection with a separate automated mass scanning campaign targeting FortiGate devices that Amazon Threat Intelligence exposed earlier this year. "The campaign shows a heavy focus on Small and Medium Businesses (SMBs) with fewer than 200 employees," SOCRadar explained. "The actor targets multiple sectors and regions, with notable emphasis on the United States and India. The IT services sector appears to be a key target. This targeting choice likely helps the actor maximize downstream access, as compromised service providers can create access paths into customer environments." Perhaps the most interesting finding is that FortiBleed appears to be part of a broader, multi-vendor initial access operation that's orchestrated to not only target Fortinet devices, but also breach Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers using automated brute-forcing since February 28, 2026. In all, the attackers are estimated to have launched no less than 659 credential-harvesting pipelines between May 31 and June 15, 2026, resulting in the identification of over 110 million credentials. This included - 14.8 million Remote Authentication Dial-In User Service (RADIUS) credentials 924,000 NTLM hashes 130,000 Kerberos hashes 89 million MySQL authentication tokens The FortiBleed campaign takes place over five stages - Perform widespread reconnaissance using tools like Masscan and Shodan to identify vulnerable internet-facing FortiGate firewalls, followed by using a custom utility dubbed FortiProbe-fast and GeoSplit to filter FortiGate systems and group them by country, respectively. Compromise the devices with a credential checker named "forticheck" that specifically targets FortiGate's administrative panel and SSL-VPN portal, along with using tools to obtain administrative SSH access via credential stuffing and dictionary attacks. Upon establishing access via SSH, FortigateSniffer is deployed to passively intercept authentication traffic across 24 protocols (e.g., TACACS+, Kerberos, RPC, SMB, LDAP, SMTP, FTP, Telnet, RDP, WinRM, MS-SQL, MySQL, PostgreSQL, and RADIUS) using native FortiOS diagnostic commands, making it possible to harvest cleartext credentials and password hashes. The password hashes are cracked using Hashmat and Hashtopolis, and orchestrated by a Telegram bot named HASHBOT, after which they are used for lateral movement, Active Directory enumeration, Kerberos validation, and SMB authentication. Sensitive data from network shares is exfiltrated while stolen session cookies are used to maintain persistent, authenticated access. "The group does not treat all targets equally," SOCRadar said. "Instead, targets are ranked according to economic value before exploitation resources are allocated." What's more, the sniffing mechanism includes a geofencing filter that restricts operations to specific IP ranges, not to mention limiting the activity to between 7 a.m. and 6 p.m. Moscow Time. According to a timeline of events shared by SpyCloud, the FortiGate-related capture cycle is said to have commenced on May 19, 2026, with the hash cracking infrastructure set up towards the end of the month. "The operation runs in a pipeline of 300-minute (five-hour) cycles, with status every minute," Zenox said. "In each cycle it loads a regional target list [...] and validates with 1,000 simultaneous threads, displaying counters of success, failure, timeout, and warning. In the first cycles, the successful validation rate hovered near 90%." The Brazilian cybersecurity company also said it found certain username and password pairs to be repeated across thousands of distinct IP addresses, raising the possibility that the accounts may have been planted by the attacker as a clandestine backdoor entry point. "The frequency counts were produced by aggregating the username:password column of the actor's own validated-credentials file, all_valid.txt, which is a device-keyed inventory in the format IP:PORT:USERNAME:PASSWORD (one record per firewall, 21,976 records)," Acassio Silva, co-founder and head of threat intelligence at ZenoX, told The Hacker News. "The same pairs also appear in the actor's input target list EU.txt (the file their Go scanner reloads and re-validates every cycle, also IP:PORT:USER:PASS) and in downstream derivatives (valid_*.txt, matched_targets*, corps.txt, targets_300M_plus.txt, and the loot JSONs). In all_valid.txt, adminin:ITAdmin@888 is present on 3,947 distinct devices; within the EU batch alone (EU.txt, 6,175 records) the same pair appears on 1,562 devices." The assessment that these pairs could be planted accounts rather than organic credentials stems from three factors: the same credentials being used to validate thousands of unrelated organizations, the absence of passwords from some credential sources ("top200_fortigate.txt"), and the fact that the usernames mimic legitimate Fortinet/FortiCloud services likely in an attempt to blend in with targeted environments. The development comes as a Russian-speaking account named "SantaAd" has advertised access to thousands of Fortinet devices for a starting price of $30,000, before increasing it to $60,000 hours later. However, it's unclear if this has any connection to the FortiBleed exposure. "The threat actor group behind 'FortiBleed' was not just targeting FortiGate VPNs," SpyCloud said. "They were actually targeting a range of different internet-facing appliances with a standard spray-and-pray attack chain that relies mostly on mass scanning and brute-forcing logins." FortiBleed’s Use of CyberStrike Harvester v1.5 Arctic Wolf, in a follow-up report, described FortiBleed as a campaign using a "credential pipeline that utilizes credential stuffing, password spraying, configuration harvesting, offline cracking, and post-authentication capture processing," adding the "FortiGate access becomes multi-protocol credential extraction, hash cracking, VPN-bound AD/SMB access, and file-share exfiltration." An important characteristic of the attacks is that they do not exploit any new zero-day vulnerability, with Fortinet noting that the threat actors are likely reusing credentials from previous incidents, as well as brute-forcing passwords on devices with weak passwords and that have not had multi-factor authentication (MFA) enabled. "Its defining feature is the credential feedback loop: successful perimeter access creates configuration or traffic artifacts; those artifacts produce more credentials and crackable hashes," Arctic Wolf said. "Cracked credentials feed VPN, Kerberos, SMB, and share-access validation, and validated access then supports further collection and exfiltration." The activity also involves exporting configuration files from internet-facing FortiGate devices and cracking the stored credential hashes, while making use of a custom information-extraction suite called "harvest_orig" that turns passive network captures into "actionable credentials, crackable hashes, web sessions, identity intelligence, and downstream attack inputs." The Go-based ELF binary, which identifies itself as CyberStrike Harvester v1.5, contains functions for reading pcap, pcapng, and FortiGate text inputs, parser and formatter functions for processing cookies, sessions, and tokens associated with the two dozen protocols. "The cracking layer is carefully engineered rather than ad-hoc," it added. "A Telegram bot accepts hash input, restricts access by Telegram username, detects hash modes, requests contextual hints, schedules jobs, allocates GPUs, launches multi-stage Hashcat workflows, monitors ETA and progress, and returns cracked results." "Hashcat modes include NetNTLMv2, FortiGate256, RAKP, MS-SQL, and multiple Kerberos formats. Hashtopolis and a custom HashPanel provide additional distributed cracking management, while setup scripts prepare GPU workers and agent enrollment." In scenarios where recovered credentials enabled access, the attackers have been found to leverage authenticated SSL-VPN tunnels for Impacket tools for Active Directory enumeration, Kerberos validation, SMB authentication, admin-share checks, SMB share spidering, and DFS/SMB collection. Affected organizations are recommended to rotate credentials, invalidate sessions, audit configuration exports, review SSL-VPN logins, inspect AD and SMB activity from VPN pools, scan for outbound SSH transfer patterns, and review SMB share access logs for bulk recursive reads. "FortiBleed demonstrates how exposed perimeter credentials can become full internal-network exposure," the company added. "The most important finding is the engineering discipline around the workflow. The operator lab, sniffer panel, CyberStrike Harvester, cleaning scripts, Hashcat/Hashtopolis infrastructure, Kerberos QA tools, domain/folder/revenue enrichment, and SMB/DFS tools form a repeatable system." Calling the activity an "indiscriminate internet wide sweep," CloudSEK said the toolchain devised by the threat actors feeds a revenue-sorted catalog of remote access targets likely for sale on underground markets. "The directory also contains at least one live SSL VPN configuration file pointing into a victim network, confirming that the operators held usable, active access, not merely a list of cracked passwords," it said. (The story was updated after publication on June 24, 2026, with additional insights from Arctic Wolf, CloudSEK, and Zenox.)
thehackernews.comJun 23, 2026extracted
What the Fortibleed campaign means for organizations running FortiGate firewalls
What the Fortibleed campaign means for organizations running FortiGate firewalls A massive credential-harvesting campaign targeting FortiGate firewalls has exposed thousands of organizations to potential network compromise, and a trove of attacker tools, scripts, and credentials left inadvertently exposed on a server has given researchers an unusually detailed look at how the operation worked. Analysts from ZenoX and CloudSEK have pieced together the full attack chain from the FortiBleed leak, revealing a sophisticated, highly automated pipeline that in some cases achieved full domain-level control of victim networks. The attackers’ modus operandi The attackers scanned the internet for FortiGate firewalls and SSL VPN gateways with exposed management interfaces, and logged in with previously compromised credentials (from previous Fortinet leaks and infostealer logs) or by brute-forcing them. They intercepted live authentication traffic passing through the compromised firewall to extract credentials from 24 different protocols, then rented GPU capacity on demand from Vast.ai and orchestrated the cracking of password hashes through a distributed hash-cracking framework, controlled via a Telegram bot. The same bot and GPU pool were used to crack Active Directory and Kerberos hashes for specific corporate targets. They also added their own administrator accounts on thousands of devices, with names designed not to raise suspicion: forticloud-sync, forticloud-tech, support_fortinet, Technical_support, etc. From inside the network, they pivoted using OpenFortiVPN client configurations and a toolkit built around the Impacket Python library, which allowed them to originate traffic through the compromised VPN tunnel as if they were a legitimate internal host They used an automated script to perform full Active Directory audits and password spraying tools to test cracked credentials across SMB shares, as well as a file-spider script that walked network shares recursively, opening scripts and configuration files in search of embedded passwords. Throughout the operation, the attackers used CyberStrike, a legitimate open-source penetration testing AI agent, to automate reconnaissance, interaction with FortiGate management panels, vulnerability scanning, and OSINT enrichment. How to check whether you’ve been affected The scale and sophistication of the operation is notable, but the immediate question for most organizations is simpler: are we in the dataset? SOCRadar and Hudson Rock have made available two free FortiBleed Checkers, to allow organizations to query their domains against the FortiBleed dataset. There’s also a list of IP addresses associated with devices with known credentials and configuration dumps, courtesy of security researcher Kevin Beaumont. If your organization is on one of the lists, Beaumont’s advice is to disconnect the devices from the internet and rebuild them from scratch (i.e., do a factory reset and reconfigure them from a clean baseline). It that’s not an option, he advises: Removing ALL admin accounts and creating new ones, with multi-factor authentication enabled Updating the device to the latest available firmware Inspecting the devices for changes made by the attackers (e.g., changed firewall rules) and looking for indicators of compromise in the logs Rotating IPsec site-to-site VPN tunnel keys or certificates AT BOTH ENDS Fortinet also advises checking for signs of lateral movement (new VPN users, unexpected password resets, or VPN from unexpected locations) and, if the device uses Active Directory or LDAP authentication, treating that account as compromised. “Monitor your AD for its use for authentication elsewhere or the creation of additional accounts and monitor your network for lateral movement,” the company said. What all Fortinet operators should do right now Even organizations that don’t appear in the dataset should treat this as an opportunity to harden their FortiGate posture. But, they should also: Take management interfaces off the public internet, and restrict access to them to trusted internal networks Enable phishing-resistant MFA on all VPN and device management logins Rotate all FortiGate admin and SSL VPN credentials, even if the organization does not appear in the dataset (as it may be incomplete) Remove or disable unnecessary accounts, including default or generic administrator accounts Update to the latest FortiOS version and force all administrators to re-authenticate afterward, so that credentials are stored more securely Audit Active Directory for unauthorized accounts, new service accounts, and privilege escalation events. (Beaumont’s investigation found direct evidence of access to internal Active Directory environments at a significant number of affected organizations, consistent with ransomware pre-positioning.) UPDATE (June 29, 2026, 04:20 a.m. ET): “FortiGate was the largest single target set present on the brute-forcing server, but it still accounts for less than a third of the internet-facing endpoints these operators scanned,” SpyCloud researchers found after analyzing the leaked dataset of the suspected initial access broker. They also targeted/collected the URLs of Synology DSM login portals and user login portals of Sophos firewalls, but it’s “unclear whether the attackers progressed past the initial scanning phase.” “The actor also appears to have targeted database servers – a dedicated MSSQL checker worked through 163,650 servers across roughly 2.1 billion login attempts. It surfaced two hits, both with the sa administrator account, on live SQL servers,” they added. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 23, 2026extracted
74,000 Fortinet firewall credentials exposed in FortiBleed data leak
74,000 Fortinet firewall credentials exposed in FortiBleed data leak A Russian-speaking cybercriminal group has stolen credentials contained in the configuration files of nearly 74,000 Fortinet firewalls and VPN gateways around the world. The data was accidentally exposed by the group on a server, along with other artifacts and tools, and the exposure was noticed by security researcher Volodymyr “Bob” Diachenko. He raised the alarm last weekend, and other researchers have since analyzed the exposed dataset. “I have worked with several orgs listed, and can confirm the logins and passwords are real,” security researcher Kevin Beaumont said. “Many of the devices sampled are on fairly recent patches. The data appears to have come from exports of config from the devices, as it includes things which are only visible from the device itself.” How the credentials were compromised According to Diachenko, the group conducts automated large-scale credential harvesting by intercepting SSL VPN authentication hashes, cracking them on a 45-GPU cluster managed via Hashtopolis, and uses the passwords to pivot into internal Active Directory environments. Hudson Rock researchers say that the group successfully targeted 73,932 unique firewall URLs across 194 countries. “In a majority of cases, the Fortigate Management Interface is exposed to the internet on impacted devices,” Beaumont noted. While the 15,000+ FortiGate configuration files leaked in 2025 were harvested by exploiting vulnerabilities in the OS running on FortiGate appliances, Fortinet believes that this latest leak – dubbed FortiBleed – includes data collected during previous incidents and via brute-forcing. Beaumont posited that while Fortinet strengthened how it stores passwords in early 2025 by switching to a more crack-resistant method (PBKDF2 with randomized salt), many devices still store credentials using the older, weaker method (SHA-256 with salt), which is vulnerable to cracking via brute-force attacks. How to check if you’re affected Hudson Rock launched a look-up tool for organizations to check whether their Fortinet credentials have been found in the data leak. Many high-profile organizations are affected, including Samsung, Siemens, Foxconn, Oracle, Accenture, DHL, Infosys, and Fortinet. The list also includes many government agencies and organizations in critical infrastructure sectors. “At least four organizations across Japan, Taiwan/Vietnam, Iraq, and Turkey were fully compromised — including a Turkish NATO defense contractor whose classified defense documents were exfiltrated,” Diachenko revealed. Organizations using Fortinet firewalls and gateways should use the look-up tool and, if their domains and IP addresses are on the list, they should assume compromise and check for compromised accounts, backdoor users, and altered security controls. If evidence of compromise is discovered, a full investigation is warranted. The affected devices should be upgraded to the latest FortiOS release and their management interface pulled from the internet (if possible). Credentials should be rotated, multi-factor authentication enforced on all accounts, and admins should log in to force the system to re-hash passwords using the more secure PBKDF2 standard, Hudson Rock advised. UPDATE (June 29, 2026, 04:20 a.m. ET): “FortiGate was the largest single target set present on the brute-forcing server, but it still accounts for less than a third of the internet-facing endpoints these operators scanned,” SpyCloud researchers found after analyzing the leaked dataset of the suspected initial access broker. They also targeted/collected the URLs of Synology DSM login portals and user login portals of Sophos firewalls, but it’s “unclear whether the attackers progressed past the initial scanning phase.” “The actor also appears to have targeted database servers – a dedicated MSSQL checker worked through 163,650 servers across roughly 2.1 billion login attempts. It surfaced two hits, both with the sa administrator account, on live SQL servers,” they added. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 18, 2026extracted
VMware離れの受け皿になるか Synologyが描く新たな復旧戦略
��Ƃ̃o�b�N�A�b�v�^�p�͓]���_���}���Ă���BVMware�ꋭ����̏I���A�I�������郉���T���E�F�A�A������AI�̑䓪�B�����������ω��̒��ŁASynology�̓o�b�N�A�b�v�̖������̂��̂����������Ƃ��Ă���B���̑S�e�����|�[�g����B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@��Ƃ̃o�b�N�A�b�v�헪�͑傫�ȓ]���_���}���Ă���B�����T���E�F�A�U���̍��x���ɂ���āA�P�Ƀf�[�^��ۑ����邾���ł͏\���Ƃ͌����Ȃ��Ȃ����B�U���҂͖{�Ԋ������łȂ��o�b�N�A�b�v���̂��̂�W�I�ɂ���悤�ɂȂ�A��Ƃɂ́u�m���ɕ����ł��邱�Ɓv������܂ňȏ�ɋ��߂��Ă���B �@�����āABroadcom�ɂ��VMware������̃��C�Z���X�̌n�ύX���A�����̊�Ƃ����z����Ղ̌�������i�߂Ă���B�uNutanix�v��uProxmox�v�Ȃǂ̉��z����Ղւ̈ڍs�╡�����̕��p���i�݂���A�o�b�N�A�b�v���i�ɂ�����v���b�g�t�H�[���Ɉˑ����Ȃ��_������߂��Ă���B �@�����������A��p�̃X�g���[�W�x���_�[�ł���Synology�́A�o�b�N�A�b�v��p�A�v���C�A���X�uActiveProtect�v�ɓ��ڂ����G���^�[�v���C�Y�����o�b�N�A�b�v��pOS�̍ŐV�ŁuActiveProtect Manager 2.0�v�iAPM 2.0�j�\�����B�����i�͏]���̃o�b�N�A�b�v�@�\����������ƂƂ��ɁAAI�����p�����ُ팟�m��}���E�F�A�����荞�݁u�T�C�o�[���W���G���X�v���b�g�t�H�[���v�Ƃ��Ă̐i����ڎw���Ă���B �@2026�N6��2���5���ɑ�p�E��k�s�ŊJ�Â��ꂽ�uCOMPUTEX TAIPEI 2026�v�Ŕ��\���ꂽ�����i�̏ڍׂ����|�[�g���悤�B �@Synology��2000�N�ɐݗ����ꂽ��p��ƂŁA���{�ł͌l�����⒆����ƌ�����NAS�iNetwork Attached Storage�j�x���_�[�Ƃ��ĔF�m����Ă���B�ߔN�͒P�Ȃ�X�g���[�W�x���_�[����̒E�p��i�߂Ă���A�o�b�N�A�b�v��Ď��J�����A�v���C�x�[�g�N���E�h�Ȃǃ\�t�g�E�F�A�̈�ɂ����Ƃ��g�債�Ă���B �@���̒��ł����Ђ����͂��Ă���̂��o�b�N�A�b�v���Ƃ��B�o�b�N�A�b�v�\�t�g�E�F�A�Ɛ�p�A�v���C�A���X������ActiveProtect�́A�o�b�N�A�b�v���̍\�z�E�^�p���ȑf�����鐻�i�Ƃ��ēW�J����Ă���B �@Synology�ɂ��ƁA���Ђ̃o�b�N�A�b�v���i�Q�ɂ���Đ��E��3000���ȏ�̃G���e�B�e�B���ی삳��Ă���Ƃ����B���\���ꂽAPM 2.0�́A���̃o�b�N�A�b�v��Ղ�����Ɋg��������̂��B �@����̔��\�ōł��傫�ȃe�[�}�̈���A�ی�Ώۃv���b�g�t�H�[���̊g�傾�낤�B�]���Ή����Ă����uMicrosoft 365�v�ɉ����A�V���ɁuAzure VM�v�uAWS EC2�v�uGoogle Workspace�v�uNutanix AHV�v�uProxmox VE�v���T�|�[�g�����B �@���̔w�i�ɂ͉��z���s��̕ω�������B����܂Ŋ�Ƃ̉��z����Ղ�VMware���f�t�@�N�g�X�^���_�[�h���������A�ŋ߂̓R�X�g��C�Z���X�̌n�̕ω����A�ʂ̃n�C�p�[�o�C�U�[�ւ̈ڍs�����������Ƃ������Ă���B �@Synology�͂��������܂��A�P�Ƀo�b�N�A�b�v���擾���邾���łȂ��A�قȂ鉼�z��ՊԂł̕������\�ɂ����B��̓I�ɂ́AVMware�Ŏ擾�����o�b�N�A�b�v��Nutanix��Proxmox�ɕ����ł���B�t�����̕����ɂ��Ή����A�ڍs�v���W�F�N�g���Q�������̏_������߂�B �@�����\�̃f���ł́AVMware�̉��z�}�V����Proxmox���ɃC���X�^���g���X�g�A����l�q���Љ�ꂽ�B�o�b�N�A�b�v���ڍs�c�[���Ƃ��Ă����p�ł��邱�Ƃ�����������B �@���̑��A�uAzure Blob Storage�v��V���ȃo�b�N�A�b�v�R�s�[�您��ъK�w����Ƃ��Ēlj��������Ƃ��������낤�B�uMicrosoft Azure�v�ʼn^�p���Ă��鉼�z�}�V��������Ƃ��A����܂ł̓I���v���~�X���̃o�b�N�A�b�v�T�[�o����f�[�^�����߂��K�v���������B�����AAPM 2.0�ł�Azure Blob Storage�ɕۊǂ��ꂽ�o�b�N�A�b�v�f�[�^���璼��Azure���ɕ����ł���B�L��l�b�g���[�N���o�R����f�[�^�]�����팸�ł��邽�߁A�������Ԃ�ʐM�R�X�g�̗}���ɂȂ���B �@����̔��\�ł�����̒��ƂȂ����̂��AML�i�@�B�w�K�j���܂�AI�����p�����ُ팟�m�@�\���BSynology�͋ߔN�̋��Г����ɂ��āA�U���ґ�������AI�����p���鎞��ɓ������Ɛ�������B����ɑR���邽�߁A�h�䑤�ɂ�AI�̊��p���s�����Ƃ����l������A�V���ɁuAI-powered Anomaly Detection�v�����������B �@���̋@�\�͉ߋ�30�̃o�b�N�A�b�v�������w�K���A�����Ƃ̃x�[�X���C�����\�z����B���̏�ŁA�o�b�N�A�b�v�擾���Ɉُ�ȕύX�����ʂ̃t�@�C���X�V�A��ʍ폜�A�t�@�C���G���g���s�[�̕ω��Ȃǂ͂��A�����T���E�F�A�ɂ��Í�����s�R�ȃf�[�^���ς̒�������o����B �@�����I�Ȃ̂͌p���w�K�̎d�g�݂��B�Ǘ��҂͌��o���ʂɑ��Đ���ȕύX�ł���u�N���[���v�Ɣ���ł���B�V�X�e���͂��̌��ʂ��w�K���A�댟�m�����炵�Ȃ��猟�o���x�����߂Ă����B�܂��A�s�R�ȃo�b�N�A�b�v�f�[�^���u������@�\���lj����ꂽ�B�^�킵���o�b�N�A�b�v�͈�ʃ��[�U�[�ɂ�镜����_�E�����[�h�𐧌����A�Ǘ��҂݂̂������ł���悤�ɂȂ�B �@�T�C�o�[���W���G���X�̋����Ɍ������@�\�͂��ꂾ���ł͂Ȃ��BSynology�̓o�b�N�A�b�v�擾�������łȂ��������̈��S������ɂ��͂�����B�V���ɓ��������uMalware Scanning�v�@�\�́A�����O�Ƀo�b�N�A�b�v�f�[�^������������̂��B�uBitDefender�v��uESET�v�uMicrosoft Defender�v�Ȃǂ����s����O���T�[�o�ƘA�g���A�o�b�N�A�b�v�f�[�^���X�L�������Č��ʂ��Ǘ��҂ɒʒm����B �@�����T���E�F�A��Q�ł́A�����ς݂̃f�[�^������ĕ������Ă��܂��A�Ăъ������������P�[�X������B������APM 2.0�ł́A�}���E�F�A�����o���ꂽ�ꍇ�ɉߋ��̃o�b�N�A�b�v�������̂ڂ��ĕ��͂��A���S�Ȑ���������I�ɓ��肷��d�g�݂����������B�P�Ɂu�������Ă���v�ƒʒm����̂ł͂Ȃ��u�����\�Ȑ��퐢��v����邱�Ƃŕ�����Ƃ��x������l�����B���̑��A�G�A�M���b�v���Ƒg�ݍ��킹�邱�ƂŁA�{�Ԋ�����藣���ꂽ������Ղ̍\�z���\�ɂȂ�B �@�o�b�N�A�b�v�^�p�̌�������APM 2.0�̏d�v�ȃe�[�}���B �@���̑�\�Ⴊ�uGlobal Source-side Deduplication�v�ł���B�������_�╡���V�X�e���ɂ܂�����d���f�[�^���\�[�X���Ŕr�����A�o�b�N�A�b�v�]���O�Ƀf�[�^�ʂ��팸����B����ɂ���ăX�g���[�W�e�ʂ̐ߖ��łȂ��A�N���E�h�o�b�N�A�b�v���̒ʐM�ʍ팸�����҂ł���B �@�܂��A�����o�b�N�A�b�v�@�\�ɂ���ĐV�K�쐬���ꂽ���z�}�V���ɕی�|���V�[�������K�p�ł���悤�ɂȂ����B�s�v�ɂȂ������[�N���[�h�ɂ��Ă͍폜�P�\���Ԃ�ݒ�ł��邽�߁A�^�p�S���҂̊Ǘ����ׂ��y���ł���BSynology�ɂ��ƁA�����p�̃��f�B�A��Ƃ�APM 2.0�Ɉڍs�������ƂŁA�����R�X�g��65���팸���A�X�g���[�W�g�p�ʂ�75���팸�����Ƃ����B �@����̔��\���猩���Ă���̂́ASynology���o�b�N�A�b�v���i�̋@�\�������������ݍ��݁A�T�C�o�[���W���G���X�s����������Ă��邱�Ƃ��B �@VMware���S���������z����Ղ̑��l����AI�����p����U���҂̑����A�����ă����T���E�F�A��̍��x���ȂNJ�Ƃ���芪�����ω��ɑΉ����邽�߁AAPM 2.0�̓o�b�N�A�b�v�擾����ُ팟�m�A���S�ȕ����܂ł���т��Ďx����������i�����Ă���B �@����AI-powered Anomaly Detection��Malware Scanning�́A�]���́u�o�b�N�A�b�v���ďI���v�Ƃ������z����A�u���S�ɕ����ł����Ԃ��ێ�����v�Ƃ����l�����ւ̓]�����ے�����@�\�ƌ����邾�낤�B �@�����Synology�́A��p�A�v���C�A���X�ɉ����A�����̉��z����ŗ��p�ł���uVirtual ActiveProtect Appliance�iVAPA�j�v�̒��\�肵�Ă���B�n�[�h�E�F�A�̔������łȂ��\�t�g�E�F�A�W�J�ւ����ݏo�����ƂŁA���Ђ̓G���^�[�v���C�Y�����f�[�^�ی�s��ł���Ȃ鑶�݊������߂悤�Ƃ��Ă���B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpJun 16, 2026extracted
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems. The activity has been attributed by Volexity to a threat cluster it tracks as VerdantBamboo, which it said overlaps with hacking groups known as Clay Typhoon (Microsoft), UNC5221 (Google), and Warp Panda (CrowdStrike). The cybersecurity company said it discovered the intrusion during an incident response engagement in September 2025, when it emerged that the adversary had compromised an unnamed victim's Egnyte Storage Sync system by exploiting a local privilege escalation flaw to deploy BRICKSTORM. The issue was addressed in Storage Sync version 13.13, released in March 2026. "The appliance had periodically been accessed by VerdantBamboo via IP addresses assigned through the victim organization's web SSL VPN," researchers Damien Cash, Paul Rascagneres, Steven Adair, and Tom Lancaster said in a technical report published last week. "The threat actor used the malware's proxying capabilities deployed on the Storage Sync system, along with compromised credentials, to access the victim's Microsoft 365 (M365) environment." It's assessed that these steps were undertaken to blend in with legitimate network traffic and evade Conditional Access policies, with the initial compromise occurring at least 18 months before. Following the initial remediation, VerdantBamboo is said to have staged a return, breaching the same organization by using stolen administrative credentials to connect to the firewall, and then abusing that access to configure web SSL VPN access to the device, connect to other systems, and deploy additional malware to a Synology Network Attached Storage (NAS) appliance. Further investigation has since uncovered that the threat actor had in fact compromised the victim organization's Managed Services Provider (MSP), specifically infecting its MSP's pfSense firewall with a BSD variant of BRICKSTORM around the same time the victim's Storage Sync system was also breached. It's believed that the victim was compromised through the threat actor's breach of the MSP. The two malware families deployed to the NAS appliance over SSH are as follows - PLENET (aka GRIMBOLT), a cross-platform backdoor developed in .NET Core and a new version of BRICKSTORM compiled using native ahead-of-time (AOT) compilation. It supports interactive shell, remote command execution, file manipulation, and command-and-control (C2) server switching. AGENTPSD, a Python-based reverse shell that likely functions as a fallback in case the primary implant ceases to function It's worth noting that the use of PLENET in the wild was reported by Google earlier this February in connection with attacks mounted by a suspected China-nexus threat cluster dubbed UNC6201 that exploited a vulnerability in Dell RecoverPoint for Virtual Machines (CVE-2026-22769, CVSS score: 10.0) as a zero-day since mid-2024. "VerdantBamboo is a highly sophisticated threat actor that seeks to leverage a combination of living-off-the-land techniques and malware deployment on systems that traditionally do not or cannot run EDR software," Volexity said. "This threat actor appears to have good knowledge of proprietary appliances, allowing them to deploy malware with customized persistence mechanisms. They also appear to have operational security discipline aimed at leveraging a limited number of domains and IP addresses per victim and setting up customized implant naming and persistence on a per-device basis."
thehackernews.comJun 8, 2026extracted
Chinese APT deploys new malware to keep access to hacked networks
A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD. An investigation into the incident revealed that the threat actor had gained access to the victim network at least 18 months before detection, and had also compromised the victim organization's managed services provider (MSP). UNC5221 is also tracked as VerdantBamboo and has been involved in attacks that exploited zero-day vulnerabilities in edge devices since at least 2023. The threat actor used the Brickstorm backdoor undetected in the environments of various targets in the United States for more than a year until the breaches were discovered around March 2025. Researchers describe Brickstorm as "an advanced malware implant." Initial variants were written in Golang, then new variants emerged, written in Rust. In April 2024, Google documented UNC5221 activity using the backdoor, and then again in September 2025, describing attacks against legal services, software-as-a-service providers, business process outsourcers, and technology companies. CISA warned about Brickstorm being deployed by Chinese hackers against VMware vSphere servers, and, more recently, Google reported that it was deployed by UNC6201 against Dell RecoverPoint for Virtual Machines. Victim hacked twice Volexity researchers responding to an incident last year found that VerdantBamboo compromised an Egnyte Storage Sync system and accessed it periodically through the victim's web SSL VPN. From this foothold and using Brickstorm proxying features and stolen credentials, the threat actor accessed the organization's Microsoft 365 enevironment. "Volexity assesses with high confidence that this was done to blend in with legitimate network traffic and evade Conditional Access policies that would have otherwise prevented access," the researchers said. Later, Volexity discovered that the hackers had spent at least 18 months on the network before being detected. Furthermore, VerdantBamboo breached the organization again after the researchers completed the remediation efforts. In the second intrusion, the attackers used stolen credentials to enable and configure SSL VPN access on the victim’s firewall, then connected to internal systems and deployed additional custom malware to a Synology NAS device. This triggered an investigation at the customer's MSP, where Volexity found that VerdantBamboo had planted a BSD variant of Brickstorm on a pfSense firewall. “Volexity concluded that this firewall, like the victim organization’s Storage Sync system, had also been compromised at least 18 months earlier.” The researchers have medium confidence that the attacker pivoted from the MSP into the victim organization's environment. Brickstorm was then deployed to the victim’s Egnyte Storage Sync appliance and to a retired Linux GroupWise email archive server. New backdoors used Once the attackers returned a few days later and re-established access to the victim’s infrastructure, they deployed the custom malware Plenet to a Synology NAS appliance. Plenet, also tracked as “Grimbolt” by Google, is a cross-platform .NET-based backdoor that offers interactive shell access, remote command execution, file manipulation, and command-and-control (C2) server switching. The researchers note that Plenet is similar in design to Brockstorm, using the WebSocket protocol for C2 communications and a multiplexing library for simultaneous data streams to the server. AgentPSD is a simple Python-based reverse shell utility that Volexity believes VerdantBamboo used as a fallback persistence mechanism if other malware was no longer accessible. The researchers discovered that AgentPSD was configured to connect to a different domain than the one Brickstorm used. However, the malware was never used as Brickstorm was still running, which supports the assessment that AgentPSD was a secondary access mechanism. During the investigation, Volexity tried to discover the infrastructure related to VerdantBamboo. The researchers created a fingerprint to identify IP addresses and domains Brickstorm used for C2 communication. Although multiple machines were identified, the threat actor took the infrastructure offline before the researchers could reveal other systems. "Between September 18 and September 23, all of the servers previously matching this pattern turned off their services on port 443." Around that time, Google also published a new report on Brickstorm's activity, which may suggest that the attacker was aware of their operations being under investigation. Volexity's describes VerdantBamboo/UNC5221 as "a highly sophisticated threat actor" that mixes living-off-the-land techniques and malware and targets systems that do not support endpoint detection and response (EDR) solutions. The researchers compiled a list of indicators of compromise (IOCs) linked to the investigated UNC5221 campaign and published them here. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 5, 2026extracted
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks," Ivanti said in an advisory. Fortinet published advisories for two critical shortcomings affecting FortiAuthenticator and FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that could result in code execution - CVE-2026-44277 (CVSS score: 9.1) - An improper access control vulnerability in FortiAuthenticator that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. (Fixed in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3) CVE-2026-26083 (CVSS score: 9.1) - A missing authorization vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. (Fixed in FortiSandbox versions 4.4.9 and 5.0.2, FortiSandbox Cloud version 5.0.6, and FortiSandbox PaaS versions 4.4.9. and 5.0.2) SAP also shipped fixes for two critical vulnerabilities - CVE-2026-34260 (CVSS score: 9.6) - An SQL injection vulnerability in SAP S/4HANA CVE-2026-34263 (CVSS score: 9.6) - A missing authentication check in the SAP Commerce cloud configuration "The vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution," Onapsis said about CVE-2026-34263. On the other hand, CVE-2026-34260 could be exploited by an attacker to inject malicious SQL statements and potentially impact the confidentiality and availability of the application. However, since the affected code only allows read access to data, the vulnerability does not compromise the integrity of the application. "It allows a low-privileged, authenticated attacker to inject malicious SQL code via user-controlled input, potentially exposing sensitive database information and crashing the application," Pathlock said. Patches have also been released by Broadcom for a high-severity flaw in VMware Fusion (CVE-2026-41702, CVSS score: 7.8) that could pave the way for local privilege escalation. The issue has been addressed in version 26H1. "VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary," Broadcom said. "A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed." Round off the list is a set of five critical vulnerabilities impacting n8n - CVE-2026-42231 (CVSS score: 9.4) - A vulnerability in the xml2js library used to parse XML request bodies in n8n's webhook handler that allows prototype pollution via a crafted XML payload, enabling an authenticated user with permission to create or modify workflows to achieve remote code execution on the n8n host. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-42232 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node, leading to remote code execution when combined with other nodes exploiting the prototype pollution. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-44791 (CVSS score: 9.4) - A bypass for CVE-2026-42232 that could result in remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44789 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node, leading to remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44790 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation, enabling an attacker to read arbitrary files from the n8n server and resulting in full compromise. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) Software Patches from Other Vendors Security updates have also been released by other vendors over the past several weeks to rectify various vulnerabilities, including - ABB Adobe Amazon Web Services AMD Apple ASUS Atlassian Axis Communications AVEVA Canon Cisco CODESYS ConnectWise Dell Devolutions Drupal F5 Fortra Foxit Software Fujitsu GitLab GnuTLS Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Intel Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Meta WhatsApp Microsoft Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA OPPO Palo Alto Networks Phoenix Contact Phoenix Technologies Progress Software QNAP Qualcomm React Ricoh Samsung Schneider Electric Siemens Sophos Spring Framework Supermicro Synology Tenable TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comMay 18, 2026extracted
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands. "The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an advisory. In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content. "Manipulated planning figures, broken reports, or deleted consolidation data can undermine close processes, executive reporting, and operational planning," Pathlock said. "In the wrong hands, this issue also creates a credible path to both stealthy data theft and overt business disruption." Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild. That said, there are many unknowns at this stage. It is not clear how many people have been affected by the hacking campaign. Nor is there any information about who is behind the activity, who is being targeted, and what their motives could be. Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass. The vulnerabilities are listed below - CVE-2026-34619 (CVSS score: 7.7) - A path traversal vulnerability leading to security feature bypass CVE-2026-27304 (CVSS score: 9.3) - An improper input validation vulnerability leading to arbitrary code execution CVE-2026-27305 (CVSS score: 8.6) - A path traversal vulnerability leading to arbitrary file system read CVE-2026-27282 (CVSS score: 7.5) - An improper input validation vulnerability leading to security feature bypass CVE-2026-27306 (CVSS score: 8.4) - An improper input validation vulnerability leading to arbitrary code execution Fixes have also been released for two critical FortiSandbox vulnerabilities that could result in authentication bypass and code execution - CVE-2026-39813 (CVSS score: 9.1) - A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. (Fixed in versions 4.4.9 and 5.0.6) CVE-2026-39808 (CVSS score: 9.1) - An operating system command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. (Fixed in version 4.4.9) The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that could allow an attacker to view sensitive information. The company said it's being actively exploited, although there are no insights into the in-the-wild exploitation associated with the bug. "SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made," Kev Breen, senior director of threat research at Immersive, said. "A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Apple ASUS AVEVA Broadcom (including VMware) Canon Cisco Citrix CODESYS D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal Elastic F5 Fortinet Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NETGEAR Node.js NVIDIA ownCloud Palo Alto Networks Phoenix Contact Progress Software QNAP Qualcomm Rockwell Automation Ruckus Wireless Samsung Schneider Electric Siemens SonicWall Splunk Spring Framework Supermicro Synology TP-Link WatchGuard, and Xiaomi
thehackernews.comApr 15, 2026extracted
Why ransomware is now after your data — and how to protect your home storage | Kaspersky official blog
Today — March 31 — is World Backup Day. And every year, most people tell themselves, “I’ll get around to that tomorrow”. But even if you’re one of the responsible ones who regularly backs up their docs, photo archives, and the entire operating system — you’re still at risk. Why? Because ransomware has learned how to specifically target everyday users’ backups. Why home users are in the crosshairs In the not-so-distant past, ransomware was mostly a big business problem. Attackers focused on corporate servers and enterprise backups because freezing a major company’s production process or stealing all their information and customer databases usually meant a massive payout. We’ve seen plenty of those cases over the last few years. However, the “small-fry” market has become just as tempting for cybercriminals — and here’s why. For starters, attacks are automated. Modern ransomware doesn’t need a human operating it manually. These programs scan the internet for vulnerable devices and, upon finding one, encrypt everything indiscriminately without the hacker getting involved. This means a single attacker can effortlessly hit thousands of home devices. Second, because of this broad reach, the ransom demands have become more “affordable”. Regular users aren’t asked for millions, but “only” a few hundred or thousand dollars. Many people are willing to pay that amount without involving the police — especially when family archives, photos, medical records, banking documents, and other personal files are on the line, with no other copies in existence. And when you multiply those smaller payouts by thousands of victims, the hackers walk away with very tidy sums. And finally, home devices are usually sitting ducks. While corporate networks are guarded really well, the average home router most likely runs on factory settings with “admin” as the password. Many people leave their network attached storage (NAS) wide open to the internet with zero protection. It’s low-hanging fruit. How personal backups get attacked A home NAS drive — often called a personal cloud — is essentially a mini-computer running a specialized Linux or FreeBSD-based operating system. It houses one or more large-capacity hard drives, often combined into an array. The storage connects to a home router, making files accessible from any device on the home network — or even remotely over the internet if you’ve configured it that way. Many people buy a NAS specifically to centralize their family’s backups and simplify access for family members, thinking it’s the ultimate safe haven for their digital archives. The irony is that these very storage hubs have become the primary target for ransomware gangs. Hackers can break in relatively easily either by exploiting known vulnerabilities or simply brute-forcing a weak password. Over the last five years, there were several major ransomware attacks specifically targeting home NAS units made by QNAP, Synology, and ASUSTOR. Targeting NAS isn’t the only way hackers can get to your files. The second method relies on social engineering: basically tricking victims into launching malware themselves. Take the massive AI hype of 2025, for example. Scammers would set up malicious websites distributing fake installers for ChatGPT, Invideo AI, and other trending tools. They would lure people in with promises of free premium subscriptions, but in reality users ended up downloading and running ransomware. What ransomware looks for once it’s inside Once the malware infiltrates your system, it starts surveying its environment and neutralizing anything that could help you recover your data without paying up. It wipes Windows shadow copies. The Volume Shadow Copy Service is a built-in Windows feature for quick file recovery. Deleting this data makes it impossible to simply roll back to a previous version of a file. It scans connected drives. If you leave an external hard drive permanently plugged into your computer, the ransomware will spot and encrypt it just like any other files. It searches for network folders. If your home cloud is mapped as a network drive, the malware will follow that path to attack that too. It checks cloud sync clients. Services like Dropbox, Google Drive, or iCloud for Windows all keep local sync folders on your computer. The ransomware encrypts the files in these folders, and the cloud service then “helpfully” uploads the encrypted versions to the cloud. The golden rule of backups The classic 3-2-1 rule for backups goes like this: Three copies of your data: the original plus two backups Two different media types: for example, your computer and an external drive One copy off-site: in the cloud or elsewhere, like at a relative’s place However, this rule predates the era of ransomware. Today we need to update it with one vital condition: another copy must be completely isolated from both the internet and your computer at the time of an attack. The new rule is 3-2-1-1 — a bit more of a mouthful, but much safer. Following it is simple: get an external hard drive that you plug in once a week, back up your data, and then unplug it. What you actually need to back up Photos and videos. Wedding photos, a baby’s first steps, family archives — these are the memories people will pay for to get back. Digital scans or photos of essential documents for every family member — everything from passports to medical records, including old archives. Two-factor authentication data. If your authenticator app only lives on your phone and you lose it, you may also lose access to all your protected accounts. Many apps let you back up your authentication data. If you use a password manager, make sure it’s syncing to a secure cloud or has an export function. Privacy-focused messaging apps don’t always store your history in the cloud. Business correspondence, important agreements, and contacts could vanish if they aren’t backed up. What to do if your data is already encrypted Don’t panic. Check out our Free Ransomware Decryptors page. We’ve collected a library of decryption tools that might help you get your data back without paying up. How to secure your backups Don’t leave your external backup drive plugged in all the time. Connect it, copy your files, and unplug it immediately. Set up automated cloud backups, but make sure your cloud provider keeps a version history for at least 30 days. If your current plan doesn’t offer this, it’s time to upgrade or switch providers. Stick to the 3-2-1-1 rule: original files on your computer, plus an external drive that you only plug in periodically, plus cloud storage. That’s three copies, two media types, one copy offline, and one off-site. Cut off internet access to your network storage. If you have a home network drive, make sure that it’s inaccessible from the internet without a password — and that the password isn’t “admin”. Disable any remote access features you don’t actually use, and make sure your firmware is up to date. Actually, keep everything up to date. Most attacks exploit known vulnerabilities that have long been patched. Enabling auto-updates for your router, NAS, and computer only takes a few minutes of setup but effectively slams the door on hundreds of known security holes. Steer clear of “free” versions of paid software. Fake installers for pirated software or game cheats are some of the primary delivery channels for ransomware. By the way, Kaspersky Premium sniffs out these threats and blocks them before they even launch. Be sure to enable the System Watcher feature in our Windows security suites. This feature logs every operating system event to help track down threats like ransomware and either block them or roll back any damage they’ve already done. Back up your authenticator app. The easiest move is to migrate your authentication tokens to Kaspersky Password Manager. It keeps them securely encrypted in the cloud alongside your passwords and sensitive docs, while syncing them across all your devices. That way, if your phone gets swiped or fried, you aren’t locked out of your accounts and vital data. Test your backups. Every few months, try restoring a random file from your archive. You’d be surprised how often a seemingly successful backup turns out to be corrupted or glitchy. It’s better to catch those glitches now while you still have the originals to fix the problem.
kaspersky.comMar 31, 2026extracted
Synology製品に緊急の脆弱性 認証なしでリモート操作の恐れ
Synology�́ADSM�Ȃǂ�OS�ɔC�ӂ̃R�}���h�����u�Ŏ��s�����d��ȐƎ㐫�����݂��邱�Ƃ����\�����BCVSS�X�R�A9.8�Ɛ[���ŁA�F�Ȃ��Ɉ��p����鋰�ꂪ����B�Ώې��i�̑��₩�ȃA�b�v�f�[�g�ƁATelnet�̖��������������������B ���̋L������������ł��B����o�^����ƑS�Ă������������܂��B �@Synology��2026�N3��19���i���n���ԁj�A���Ђ̃l�b�g���[�N�X�g���[�WOS�uDiskStation Manager�v�iDSM�j�ɏd��ȐƎ�i�������Ⴍ�j���uCVE-2026-32746�v�����݂��邱�Ƃ����\�����B �@���p�����ƁA�O������̕s���ȑ���ɂ���Đ[���ȉe������\��������B���ʐƎ㐫�]���V�X�e���iCVSS�jv3.1�̃X�R�A��9.8�Ő[���x�u�ً}�v�iCritical�j�ƕ]������Ă���A���ӂ��K�v���B �@���̖��́A�uGNU Inetutils�v�Ɋ܂܂��utelnetd�v�ɋN��������̂ŁA�o�[�W����2.7�܂łɉe������B�uLINEMODE�v��SLC�T�u�I�v�V���������ɂ����āA�����o�b�t�@�[�̗e�ʊm�F���s�\���Ȃ܂������݂��s���A���ʂƂ��ė̈�O�������݂���������B���̋����͓T�^�I�ȃo�b�t�@�[�I�[�o�[�t���[�ɊY�����A�U���҂��H�����f�[�^�𑗂荞�ނ��ƂŔC�ӂ̃R�}���h�����s�ł��鋰�ꂪ����B �@���ɔF���o���ɍU������������_�����Ƃ����B�l�b�g���[�N�o�R�Œ��ڈ��p�����\��������ANAS�ɕۑ����ꂽ�f�[�^���ގ�A������A�����l�b�g���[�N�ւ̐N���g��̑��|����ɂȂ�댯��������B��Ɨ��p�ɂ����Ă̓o�b�N�A�b�v��@�����������P�[�X�������A��Q�̉e���͈͂��L���錜�O������B �@�e�����鐻�i�Ƃ��ẮADSM 7.3�^7.2.2�^7.2.1��DSMUC 3.1����������BSynology�͂��ꂼ��ɏC���ł���Ă���ADSM 7.3�ł�7.3.2-86009-3�ȍ~�ADSM 7.2.2�ł�7.2.2-72806-8�ȍ~�ADSM 7.2.1�ł�7.2.1-69057-11�ȍ~�ւ̍X�V���K�v�ƂȂ�B�ꕔ���i�iDSMUC 3.1�j�ɂ��Ă͏C����Ƃ��p�������B�����BeeStation OS 1.4��SRM 1.3�AVS600HD 1.2�͉e�����Ȃ��Ƃ����B �@��Ƃ��āA���Ђ͑��₩�ɃA�b�v�f�[�g��K�p����悤�����Ă���B�����āA�b��[�u�Ƃ���Telnet�T�[�r�X�̖��������ē����Ă���B�ݒ��ʂ̃R���g���[���p�l������^�[�~�i�����ڂ��J���ATelnet�T�[�r�X�̃�F�b�N���O�����ƂŁA�U���o�H�̎Ւf���\�ƂȂ�B���u���삪�K�v�ȏꍇ�́ATelnet�̑���ɈÍ����ʐM�ɑΉ�����SSH�̗��p�����������B �@Telnet�͒ʐM���e���Í�������Ȃ������̃v���g�R���ł���A����̉^�p���ł͈��S���̊ϓ_���痘�p�������P�[�X�������B����̖��́A�����������K�V�[�@�\�������郊�X�N��������ƂȂ����BSynology���i�̗��p�҂�Ǘ��҂ɂ́A�ݒ�̌������ƌp���I�ȍX�V�Ή������߂���B Copyright © ITmedia, Inc. All Rights Reserved.
itmedia.co.jpMar 30, 2026extracted
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to. All of it below. Let's go. ⚡ Threat of the Week Citrix Flaw Comes Under Active Exploitation — A critical security flaw in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-3055, CVSS score: 9.3) has come under active exploitation as of March 27, 2026. The vulnerability refers to a case of insufficient input validation leading to memory overread, which an attacker could exploit to leak potentially sensitive information. Per Citrix, successful exploitation of the flaw hinges on the appliance being configured as a SAML Identity Provider (SAML IDP). Your Engineers Are Drowning in Tools — Here's the Data Chainguard surveyed 1,200 engineers and tech leaders for their 2026 Engineering Reality Report. AI is buying back time but also introducing new security concerns, while technical debt, tool sprawl, and burnout keep dragging teams down. 72% say time pressure blocks new feature work; 88% report productivity loss from too many tools. Get the Full Report ➝ 🔔 Top News FBI Confirms Hack of Director Kash Patel's Personal Email Account — The U.S. Federal Bureau of Investigation (FBI) confirmed that threat actors gained access to an email account belonging to FBI Director Kash Patel, but said no government information has been compromised. The Iran-linked hacker group Handala claimed responsibility for the hack, releasing files allegedly representing photos, emails, and classified documents taken from the FBI director's inbox. "The so-called 'impenetrable' systems of the FBI were brought to their knees within hours by our team," the hackers wrote. It's unclear when the account was hacked. The U.S. government, which recently took down multiple sites operated by Iranian state actors, said it's offering up to $10 million for information on threat groups like Parsian Afzar Rayan Borna and Handala. Parsian Afzar Rayan Borna is an IT company that's been implicated in Iran's disinformation and surveillance campaigns. The company is assessed to be linked to Banished Kitten, an Iran-nexus adversary active since at least 2008 and operates the Homeland Justice and Handala Hack personas. Red Menshen Uses Stealthy BPFDoor to Spy on Telecom Networks — A China-linked state-sponsored threat actor known as Red Menshen has deployed kernel implants and passive backdoors deep within telecommunication backbone infrastructure worldwide for long-term persistence. The implants have been fittingly described as sleeper cells that lie dormant and blend into target environments, but spring into action upon receiving a magic packet by quietly monitoring network traffic instead of opening a visible connection. Initial access is usually gained by exploiting known vulnerabilities in edge networking devices and VPN products or by leveraging compromised accounts. Once inside, the threat actor maintains long-term access by deploying tools like BPFdoor. Some BPFdoor samples mimic bare-metal infrastructure, posing as legitimate enterprise platforms to blend into operational noise. Others spoof core containerization components. By embedding the implant deep below traditional visibility layers, the goal is to significantly complicate detection efforts. Rapid7 has released a scanning script designed to detect known BPFDoor variants across Linux environments. GlassWorm Evolves to Drop Extension-Based Stealer — A new evolution of the GlassWorm campaign is delivering a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, and takes commands from a C2 server hidden in a Solana blockchain memo," Aikido said. GlassWorm is the moniker assigned to a persistent campaign that obtains an initial foothold through rogue packages published across npm, PyPI, GitHub, and the Open VSX marketplace. In addition, the operators are known to compromise the accounts of project maintainers to push poisoned updates. Russian Hacker Sentenced to 2 Years for TA551-Linked Ransomware Attacks — Ilya Angelov, a 40-year-old Russian national, was sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Angelov, who went by the online aliases "milan" and "okart," is said to have co-managed a Russia-based cybercriminal group known as TA551 (aka ATK236, G0127, Gold Cabin, Hive0106, Mario Kart, Monster Libra, Shathak, and UNC2420) between 2017 and 2021. The attacks leveraged spam emails to compromise systems and rope them into a botnet that other cybercriminals used to break into corporate systems and deploy ransomware. This included threat actors affiliated with BitPaymer and IcedID. FCC Bans New Foreign-Made Routers Over Security Risks — The U.S. Federal Communications Commission (FCC) said it was banning the import of new, foreign-made consumer routers, citing "unacceptable" risks to cyber and national security. To that end, all consumer-grade routers manufactured in foreign countries have been added to the Covered List, unless they have been granted a Conditional Approval by the Department of War (DoW) or the Department of Homeland Security (DHS) after determining that they do not pose any risks. The development comes as the Indian government appears to be preparing to bar Chinese CCTV product makers, such as Hikvision, Dahua, and TP-Link, from selling their cameras from April 1, 2026, to tighten oversight under the Standardisation Testing and Quality Certification (STQC) rules, the Economic Times reported. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3055 (Citrix NetScaler ADC and NetScaler Gateway), CVE-2025-62843, CVE-2025-62844, CVE-2025-62845, CVE-2025-62846 (QNAP), CVE-2026-22898 (QNAP QVR Pro), CVE-2026-4673, CVE-2026-4677, CVE-2026-4674 (Google Chrome), CVE-2026-4404 (GoHarbor Harbor), CVE-2026-1995 (IDrive for Windows), CVE-2026-4681 (Windchill and FlexPLM), CVE-2025-15517, CVE-2025-15518, CVE-2025-15519, CVE-2025-15605, CVE-2025-62673 (TP-Link),CVE-2025-66176 (HikVision), CVE-2026-32647 (NGINX Open Source and NGINX Plus), CVE-2026-22765, CVE-2026-22766 (Dell Wyse Management Suite), CVE-2026-21637, CVE-2026-21710 (Node.js), CVE-2026-25185 aka LnkMeMaybe (Microsoft), CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591 (BIND 9), CVE-2026-2931 (Amelia Booking plugin), CVE-2026-33656 (EspoCRM), CVE-2026-3608 (Kea), CVE-2026-20817 (Microsoft Windows Error Reporting), CVE-2025-33244 (NVIDIA Apex), CVE-2026-32746 (Synology DiskStation Manager), and CVE-2026-3098 (Smart Slider 3 plugin). 🎥 Cybersecurity Webinars Your Identity Program Is Mature. So Why Are You Still Getting Breached? → Your identity program is mature. Yet hundreds of apps still operate outside it. New 2026 Ponemon research from 600+ security leaders shows exactly how big that gap is and what it costs. Now, AI agents are making it worse. This webinar breaks down the findings and shows you what to fix first. Everyone Agrees AI Agents Need Identity. Almost Nobody Knows How to Do It → Everyone agrees AI agents need identity. Few know how to actually do it. This session skips the theory and shows you what a real production deployment looks like, including how to give agents strong identities, see exactly what they're doing, and control how they behave. 📰 Around the Cyber World Fortinet FortiClient EMS Flaw Comes Under Attack — A recently patched security flaw affecting Fortinet FortiClient EMS has come under active exploitation in the wild as of March 24, 2026. The vulnerability in question is CVE-2026-21643 (CVSS score: 9.1), a critical SQL injection that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. The issue was addressed by Fortinet last month in FortiClient EMS version 7.4.5. "Attackers can smuggle SQL statements through the 'Site'-header inside an HTTP request," Defused Cyber said. Nearly 1,000 FortiClient EMS are publicly exposed. Meta Disrupts Influence Operation Linked to Iran — Meta said it disrupted an influence operation linked to Iran that employed "sophisticated fake personas" on Instagram to build relationships with U.S. users before sending political messaging. The network used accounts posing as journalists, commentators, and ordinary people to engage users and gradually introduce political narratives. A second layer of accounts amplified posts to help spread the messaging. Armenian National Extradited to U.S. in Connection with RedLine Stealer Operations — An Armenian national has been extradited to the United States over his alleged role in the administration of the RedLine infostealer malware. Hambardzum Minasyan, per court documents, allegedly developed and managed the stealer, while unnamed conspirators maintained digital infrastructure, including the command-and-control (C2) servers and administrative panels to enable the deployment of the malware by affiliates, and collected payments from the affiliates. "They allegedly responded to questions and requests from actual and potential RedLine affiliates, conspired with each other and affiliates to steal and possess the financial information, including access devices, of victims, and laundered the proceeds of cybercrime through cryptocurrency exchanges and other means," the U.S. Justice Department said. Minasyan has also been accused of registering two virtual private servers to host portions of RedLine's infrastructure, as well as two internet domains in support of the scheme, repositories on an online file sharing site to distribute the stealer to affiliates, and registering a cryptocurrency account in November 2021 to receive payments. RedLine Stealer was disrupted in an international law enforcement operation in October 2024. Minasyan has been charged with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. If convicted, he faces up to 10 years in prison for access device fraud and up to 20 years in prison for the other two counts. In June 2025, the U.S. Department of State announced a $10 million reward for information on Maxim Alexandrovich Rudometov, who is believed to be the main developer and administrator of RedLine. New Android Malware "Android God Mode" Abuses Accessibility Permissions — The Indian Cybercrime Coordination Centre (I4C) has issued an advisory, alerting users of a new Android malware called Android God Mode that abuses its permissions to accessibility services to seize control of infected devices. The malware is propagated via dropper apps that masquerade as banking, public, and utility services such as SBI YONO, Jivan Parman Patra, and RTO Challan, indicating that the campaign's focus is on targeting Indian users. "By coercing users into granting elevated Android permissions, these threats achieve near-total control over the device, enabling stealthy overlay attacks and the real-time theft of sensitive financial and personal information," the I4C said. The malware is distributed in the form of links or APK files shared through WhatsApp. Once installed, it abuses Android's accessibility services to grant itself additional permissions to harvest incoming SMS messages, send messages on the victim's behalf, access contact lists, initiate fraudulent call forwarding, and take pictures using the device's camera. Android 17 Beta Gains New Security Features — To improve security against code injection attacks, Android now enforces that dynamically loaded native libraries must be read-only. If your app targets Android 17 or higher, all native files loaded using System.load() must be marked as read-only beforehand. Another new addition is the support for Post-Quantum Cryptography (PQC) through the new v3.2 APK Signature Scheme. This scheme utilizes a hybrid approach, combining a classical signature with an ML-DSA signature. China-Linked Actors Deliver Mofu Loader and KIVARS — In recent months, Chinese-affiliated espionage clusters like DRBControl have employed DLL side-loading techniques to deliver Mofu Loader – a malware previously attributed to GroundPeony – which then drops a C++ backdoor capable of executing commands issued by an attacker-controlled server. Last year, companies and organizations in Japan and Taiwan have also been targeted by variants of a backdoor called KIVARS, which is tied to a Chinese hacking group called BlackTech. Automated Traffic Outpaces Human Traffic — HUMAN Security found that automated traffic grew eight times faster than human traffic year-over-year. "In 2025, automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period," the company said. The cybersecurity company noted that its customers experienced more than 400,000 attempted post-login account compromise attacks, more than quadruple that of 2024. U.S. Accuses China of Backing Scam Compounds — A senior U.S. official accused Beijing of implicitly backing Chinese criminal syndicates running cyber scam compounds across Southeast Asia. Speaking during a Joint Economic Committee congressional hearing about U.S. efforts to combat digital scams, Reva Price, commissioner with the U.S.-China Economic and Security Review Commission, said links have been unearthed between scam centers and the Chinese government's Belt and Road Initiative. Chinese criminal syndicates have "invested in projects linked to China's Belt and Road Initiative alongside China's state-owned enterprises," she said, adding that they "have also seen criminal leaders who appear to have gotten a pass by promoting messaging and other activities aligned with Chinese Communist Party priorities." Scam centers in Southeast Asia are often operated by Chinese crime syndicates that lure people into the region with enticing job opportunities and coerce them into participating in pig butchering or romance baiting scams by confiscating their passports and subjecting them to torture. Exploitation Against Oracle WebLogic Servers — A recently disclosed security flaw in Oracle WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts almost immediately after public exploit code was released, demonstrating how software flaws are being rapidly weaponized by bad actors. The activity, detected by CloudSEK against its honeypots, also leveraged other WebLogic flaws (CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271), as well as flaws impacting Hikvision and PHPUnit, indicating a spray and pray approach. "Attackers predominantly utilized rented Virtual Private Servers (VPS) from common hosting providers like DigitalOcean and HOSTGLOBAL.PLUS," the company said. "The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic." Security Flaws in Cisco Catalyst 9300 Series Switches — Details have emerged about now-patched vulnerabilities in Cisco Catalyst 9300 Series switches (CVE-2026-20110, CVE-2026-20112, CVE-2026-20113, and CVE-2026-20114) that could result in privilege escalation, operational denial-of-service, stored cross-site scripting (XSS), and CRLF injection. "Collectively, these vulnerabilities introduce risks to administrative trust boundaries, service availability, session integrity, and system log reliability – affecting both operational continuity and security monitoring capabilities," OPSWAT said. "CVE-2026-20114 and CVE-2026-20110 are the most operationally impactful when chained. A low-privilege Web UI user can escalate access and invoke a maintenance-mode operation, resulting in full denial of service that may require physical intervention to restore." The issues were patched by Cisco last week. Financial Institution Targeted by BRUSHWORM and BRUSHLOGGER — A modular backdoor with USB-based spreading capabilities was used in an attack targeting an unnamed South Asian financial institution, according to findings from Elastic Security Labs. The malware, dubbed BRUSHWORM, is one of the two malware components identified in the victim's infrastructure, the other being a DLL keylogger referred to as BRUSHLOGGER. "BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code," security researcher Salim Bitam said. BRUSHWORM is also responsible for running basic anti-analysis checks, maintaining persistence, command-and-control (C2) communication, and downloading additional modular payloads. BRUSHLOGGER augments the backdoor by capturing system-wide keystrokes via a simple Windows keyboard hook and logging the active window context for each keystroke session. "Neither binary employs meaningful code obfuscation, packing, or advanced anti-analysis techniques," Elastic said. "Given the absence of a kill switch, the use of free dynamic DNS servers in testing versions, and some coding mistakes, we assess with moderate confidence that the author is relatively inexperienced and may have leveraged AI code-generation tools during development without fully reviewing the output." U.K. Sanctions Xinbi — The U.K.'s Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language guarantee marketplace accused of enabling large-scale online fraud and human exploitation by supporting #8 Park (aka Legend Park), an industrial-scale scam compound in Cambodia notorious for large-scale pig butchering scams and forced labor of trafficked workers. The U.K. is the first country to sanction Xinbi. The move is designed to isolate Xinbi from the legitimate crypto ecosystem and disrupt its operations. Xinbi is estimated to have processed over $19.9 billion between 2021 and 2025. "The platform facilitates everything from 'Black U' money laundering and unlicensed OTC trades to the sale of compromised personal databases and scam infrastructure," Chainalysis said. "In the face of previous takedowns, Xinbi demonstrated significant resilience by rapidly migrating to the SafeW messaging app and launching its own proprietary payment app, XinbiPay. This evolution highlights the challenges around pursuing illicit services as they build custom financial rails to insulate themselves from platform-level disruptions." According to a report published by Elliptic last month, #8 Park is linked to a company named Legend Innovation, which, in turn, has ties to Prince Group, whose chairman, Chen Zhi, was arrested and extradited to China in connection with a crackdown on a large-scale fraud operation. #8 Park is also tied to HuiOne Group, with its payment business, HuiOne Pay (later rebranded as H-PAY), which operates a physical store within the compound. There has since been a sharp decline in incoming payments to merchants operating inside the compound beginning around February 9, 2026, with transactions almost entirely ceasing by February 13. What is Tsundere? — Tsundere is a botnet that enables system fingerprinting and arbitrary command execution on victim machines. It's notable for the use of a technique called EtherHiding to retrieve command-and-control (C2) servers stored in smart contracts on the Ethereum blockchain. The malware is suspected to be a Malware-as-a-Service (MaaS) offering of Russian origin, owing to logic that checks whether the infected host is located in a CIS country, including Ukraine, and terminates execution if so. Most recently, the use of the botnet has been linked to the Iranian state-sponsored actor MuddyWater. Jailbreaking, a Continued Risk to LLMs — New research from Palo Alto Networks Unit 42 has uncovered that prompt jailbreaking remains a practical risk to large language models (LLMs) and that a genetic algorithm-based fuzzing approach can be used to generate meaning-preserving prompt variants to trigger policy-violating outcomes against both closed-source and open-weight pre-trained models. "The broader implication is that guardrails should be treated as probabilistic controls that require continuous adversarial evaluation, not as definitive security boundaries," Unit 42 said. The findings reinforce that security for LLM applications cannot rely on a single layer, necessitating that organizations define and enforce application scope, use robust, multi-signal content controls, treat user input as untrusted and isolate it from privileged instructions, validate outputs against scope and policy, and monitor for misuse, and apply standard security controls, such as authentication, rate limiting, and and least privilege tool permissions. SEO Campaign Delivers AsyncRAT — Since October 2025, an unknown threat actor has been running an active SEO poisoning campaign, using impersonation sites of over 25 popular applications to direct victims to malicious installers, including VLC Media Player, OBS Studio, KMS Tools, and CrosshairX. The campaign uses ScreenConnect, a legitimate remote management tool, to establish initial access and to deliver AsyncRAT. "Most notable in this campaign is the RAT’s added cryptocurrency clipper, dynamic plugin system capable of loading arbitrary capabilities at runtime, and a geo-fencing mechanism that deliberately excludes targets across the Middle East, North Africa, and Central Asia," NCC Group said. AsyncRAT has also been delivered as part of a series of attacks on Libyan organizations between November 2025 and February 2026. The attacks targeted an oil refinery, a telecoms organization, and a state institution. "AsyncRAT is a remote access Trojan with a variety of capabilities, including keylogging, screen capture, and remote command execution capabilities, making it ideal for use in intelligence gathering and espionage attacks," Symantec and Carbon Black said. "It is also modular, meaning it can be updated and customized, which is attractive for attackers." Nigerian National Sentenced to 7 Years in Prison — A Nigerian man has been sentenced to more than seven years in a U.S. prison for his role in a scheme that broke into business email accounts and tricked victims into sending millions of dollars to fraudulent bank accounts. James Junior Aliyu, 31, received a 90-month prison sentence for conspiracy to commit wire fraud and money laundering. The court also ordered Aliyu to forfeit $1.2 million and repay nearly $2.39 million to the victims. Aliyu, who pleaded guilty in August 2025, acknowledged that he conspired with others, including Kosi Goodness Simon-Ebo, 31, and Henry Onyedikachi Echefu, 34, to deceive and defraud multiple American victims from February 2017 until at least July 2017. The business email compromise scheme targeted American businesses and individuals by compromising email accounts and sending false wiring instructions to deceive victims into sending money to bank accounts under their control. "Aliyu and his accomplices conspired to commit money laundering by disbursing the fraudulently obtained funds in the drop accounts to other accounts," the U.S. Justice Department said. "Co-conspirators moved the stolen money by initiating account transfers, withdrawing cash, and obtaining cashier’s checks. They also wrote checks to other individuals and entities to hide the true ownership and source of these assets. In total, Aliyu and his co-conspirators attempted to defraud victims of at least $10.4 million, and the victims suffered an actual loss of at least $2,389,130." Sensor Technology to Combat Deepfakes — Researchers at ETH Zürich have developed a sensor system that stamps a cryptographic signature onto images, video, and audio within a sensor chip at the exact moment they are captured, making it impossible to tamper with the data without being detected. "If the signatures are uploaded to a public ledger (e.g., a blockchain), anyone can verify the authenticity of videos and other data," ETH Zürich said. "The technology can, in principle, be integrated into any type of sensor or camera. It would then be possible to identify manipulated content on online platforms with minimal effort." Middle East Conflict Fuels Cyber Attacks — Threat actors have been capitalizing on geopolitical tensions in the Middle East region to spread Android spyware by distributing trojanized versions of Israel's Red Alert apps via SMS phishing messages. The espionage campaign has been codenamed Operation False Siren by CYFIRMA. ZIP archives containing lures related to the conflict are also being used to launch malicious payloads that lead to the deployment of PlugX and LOTUSLITE backdoors. These ZIP-based phishing campaigns have been attributed to a Chinese nation-state actor known as Mustang Panda. Elsewhere, an Iran-themed fake news blog site hosting malicious JavaScript has been found, leading to the deployment of StealC malware. Apple Tests Ways to Block Malicious Copy-Pastes in macOS — With the release of macOS 26.4 last week, Apple has introduced a new feature that warns Mac users if they paste harmful commands in the Terminal app to curb ClickFix-style attacks that have increasingly targeted macOS in recent months. "Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy," the message reads. "These instructions are commonly offered via websites, chat agents, apps, files, or a phone call." The alert comes with a "Paste Anyway" for those who wish to proceed. The disclosure comes as multiple ClickFix campaigns have come to light, including using a Cloudflare-themed verification page to deliver a Python-based macOS stealer dubbed Infiniti Stealer. A similar Cloudflare verification, but for Windows, has been used to launch PowerShell commands that ultimately drop StealC, Lumma, Rhadamanthys, Vidar Stealer, and Aura Stealer malware. The ClickFix strategy has also been adopted by a traffic distribution system known as KongTuke to redirect visitors of compromised WordPress websites to phishing pages and malware payloads. According to eSentire, ClickFix lures have been used to deliver EtherRAT, a Node.js-based backdoor linked to North Korean threat actors. "EtherRAT allows threat actors to run arbitrary commands on compromised hosts, gather extensive system information, and steal assets such as cryptocurrency wallets and cloud credentials," the Canadian security company said. "Command-and-Control (C2) addresses are retrieved using 'EtherHiding,' a technique to make C2 addresses more resilient by storing and updating them in Ethereum smart contracts, allowing threat actors to rotate infrastructure at a small cost and avoid takedowns by law enforcement." Recorded Future said it has identified five distinct clusters leveraging ClickFix to facilitate initial access to Windows and macOS systems since May 2024. "This indicates that the ClickFix methodology has transitioned into a standardized, high-ROI template adopted across a fragmented ecosystem of threat actors," Insikt Group said. "While visually diverse, all analyzed clusters use a consistent execution framework that bypasses traditional browser security controls by shifting the point of exploitation to user-assisted manual commands. These campaigns target a wide variety of sectors, including accounting (QuickBooks), travel (Booking.com), and system optimization (macOS)." Apple Rolls Out Mandatory Age Verification in U.K. — In more Apple news, the tech giant has rolled out mandatory U.K. age verification with iOS 26.4, requiring users to provide a credit card or ID to confirm if they are an adult before "downloading apps, changing certain settings, or taking other actions with your Apple Account." The move comes at a time when online child safety is increasingly drawing attention from regulators, causing many digital services, including social media apps and porn sites, to roll out similar checks. Discord, which announced plans to verify the ages of all its users last month, has since paused the effort until H2 2026 after concerns were raised about how IDs and personal information would be handled. Discord has reiterated that it does not receive any identifying personal information from users who need to manually verify their age. Instead, it is partnering with third-party age verification companies, who will "handle verification and only pass back your age group." The company also said it's no longer working with age verification vendor Persona, which has attracted criticism over allegations that it shared users' data with other companies and left its frontend source code exposed to the internet. 🔧 Cybersecurity Tools OpenClaw Security Handbook → It is a detailed security guide published by ZAST AI for users of OpenClaw, a multi-channel AI gateway that connects messaging platforms, LLMs, and local system capabilities. Because that combination creates a serious attack surface, the handbook covers the real risks — prompt injection, malicious skills, exposed ports, credential theft — backed by documented incidents and CVEs, with practical configuration guidance for locking it down. VulHunt → It is an open-source framework from Binarly's research team for hunting vulnerabilities in software binaries and UEFI firmware. It uses customizable rulepacks for scanning and can connect to Binarly's Transparency Platform for large-scale triage. It also supports running as an MCP server, letting AI assistants interact with it directly. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion That's the week. Some of it will age well, some of it is already being quietly exploited while you're reading this sentence. The through-line, if there is one: patience. Attackers are playing long games. The detections, the arrests, the patches — they matter, but they're almost always trailing. Stay sharp, check the CVE list, and see you next Monday.
thehackernews.comMar 30, 2026extracted
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below - CVE-2019-17571 (CVSS score: 9.8) - A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) - An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration "The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571," SAP security company Onapsis said. "It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application." CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content. "Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10," Onapsis added. The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws. On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution. Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface. "A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls," HPE said. "In some cases, this could enable resetting the admin password." "Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected," Ross Filipek, CISO at Corsica Technologies, said in a statement. "A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today's hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk." Software Patches from Other Vendors Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Arm Atlassian Bosch Broadcom (including VMware) Canon Cisco Commvault Dassault Systèmes Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Google Wear OS Grafana Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird n8n NVIDIA Palo Alto Networks QNAP Qualcomm Ricoh Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Synology TP-Link Trend Micro WatchGuard Western Digital Zoom, and Zyxel
thehackernews.comMar 11, 2026extracted
Aggiornamenti di sicurezza per prodotti Synology
Aggiornamenti di sicurezza per prodotti Synology Alert AL03/260224/CSIRT-ITA Sintesi Aggiornamenti di sicurezza sanano una vulnerabilità con gravità “media” presente in Synology Presto Client, software per il trasferimento rapido di file verso Synology Presto File Server. La vulnerabilità, qualora sfruttata in locale e con privilegi minimi, può consentire l’accesso o la modifica arbitraria dei file, compromettendo la disponibilità dei sistemi coinvolti, nonché l’integrità e la confidenzialità delle informazioni contenute. Tipologia Arbitrary File Write/Read Descrizione e potenziali impatti La vulnerabilità, classificata come Uncontrolled Search Path Element, dovuta a un controllo non adeguato del percorso di ricerca delle librerie dinamiche (DLL) durante la fase di installazione, può essere sfruttata da un attaccante locale dotato di privilegi minimi. Lo sfruttamento richiede l’interazione utente ed il posizionamento di una libreria malevola nella directory del programma di installazione. Qualora sfruttata, la vulnerabilità può consentire la lettura o la modifica non autorizzata di file sensibili, determinando una potenziale compromissione della riservatezza e dell’integrità delle informazioni. La sovrascrittura o alterazione di file critici potrebbe inoltre generare impatti sulla disponibilità dei sistemi interessati. Sebbene lo sfruttamento richieda accesso locale e l’interazione dell’utente, il livello di rischio risulta più elevato in ambienti multiutente o su sistemi condivisi, nei quali la coesistenza di più account e livelli di privilegio può agevolare abusi, escalation o movimenti laterali all’interno dell’infrastruttura. Prodotti e versioni affette Presto Client, versioni precedenti la 2.1.3-0672 Azioni di mitigazione In linea con le dichiarazioni del vendor, si raccomanda di aggiornare i prodotti vulnerabili, come indicato nel bollettino di sicurezza riportato nella sezione Riferimenti.
acn.gov.itFeb 24, 2026extracted
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
It's Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services. Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Windows components that could be abused to bypass security features, escalate privileges, and trigger a denial-of-service (DoS) condition. Elsewhere, Adobe released updates for Audition, After Effects, InDesign Desktop, Substance 3D, Bridge, Lightroom Classic, and DNG SDK. The company said it's not aware of in-the-wild exploitation of any of the shortcomings. SAP shipped fixes for two critical-severity vulnerabilities, including a code injection bug in SAP CRM and SAP S/4HANA (CVE-2026-0488, CVSS score: 9.9) that an authenticated attacker could use to run an arbitrary SQL statement and lead to a full database compromise. The second critical vulnerability is a case of a missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform (CVE-2026-0509, CVSS score: 9.6) that could permit an authenticated, low-privileged user to perform certain background Remote Function Calls without the required S_RFC authorization. "To patch the vulnerability, customers must implement a kernel update and set a profile parameter," Onapsis said. "Adjustments in user roles and UCON settings might be required to not interrupt business processes." Rounding off the list, Intel and Google said they teamed up to examine the security of Intel Trust Domain Extensions (TDX) 1.5, uncovering five vulnerabilities in the module (CVE-2025-32007, CVE-2025-27940, CVE-2025-30513, CVE-2025-27572, and CVE-2025-32467), and nearly three dozen weaknesses, bugs, and improvement suggestions. "Intel TDX 1.5 introduces new features and functionality that bring confidential computing significantly closer to feature parity with traditional virtualization solutions," Google said. "At the same time, these features have increased the complexity of a highly privileged software component in the TCB [Trusted Computing Base]." Software Patches from Other Vendors Security updates have also been released by other vendors in recent weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD AMI Apple ASUS AutomationDirect AVEVA Broadcom (including VMware) Canon Check Point Cisco Citrix Commvault ConnectWise D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal F5 Fortinet Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Thunderbird n8n NVIDIA Phoenix Contact QNAP Qualcomm Ricoh Rockwell Automation Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Spring Framework Supermicro Synology TP-Link WatchGuard Zoho ManageEngine Zoom, and Zyxel
thehackernews.comFeb 11, 2026extracted
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively Exploited
Microsoft on Tuesday rolled out its first security update for 2026, addressing 114 security flaws, including one vulnerability that it said has been actively exploited in the wild. Of the 114 flaws, eight are rated Critical, and 106 are rated Important in severity. As many as 58 vulnerabilities have been classified as privilege escalation, followed by 22 information disclosure, 21 remote code execution, and five spoofing flaws. According to data collected by Fortra, the update marks the third-largest January Patch Tuesday after January 2025 and January 2022. These patches are in addition to two security flaws that Microsoft has addressed in its Edge browser since the release of the December 2025 Patch Tuesday update, including a spoofing flaw in its Android app (CVE-2025-65046, 3.1) and a case of insufficient policy enforcement in Chromium's WebView tag (CVE-2026-0628, CVSS score: 8.8). The vulnerability that has come under in-the-wild exploitation is CVE-2026-20805 (CVSS score: 5.5), an information disclosure flaw impacting Desktop Window Manager. The Microsoft Threat Intelligence Center (MTIC) and Microsoft Security Response Center (MSRC) have been credited with identifying and reporting the flaw. "Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager (DWM) allows an authorized attacker to disclose information locally," Microsoft said in an advisory. "The type of information that could be disclosed if an attacker successfully exploited this vulnerability is a section address from a remote ALPC port, which is user-mode memory." There are currently no details on how the vulnerability is being exploited, the scale of such efforts, and who may be behind the activity. "DWM is responsible for drawing everything on the display of a Windows system, which means it offers an enticing combination of privileged access and universal availability, since just about any process might need to display something," Adam Barnett, lead software engineer at Rapid7, said in a statement. "In this case, exploitation leads to improper disclosure of an ALPC port section address, which is a section of user-mode memory where Windows components coordinate various actions between themselves." Microsoft previously addressed an actively exploited zero-day flaw in DWM in May 2024 (CVE-2024-30051, CVSS score: 7.8), which was described as a privilege escalation flaw that was abused by multiple threat actors, in connection with the distribution of QakBot and other malware families. Satnam Narang, senior staff research engineer at Tenable, called DWM a "frequent flyer" on Patch Tuesday, with 20 CVEs patched in the library since 2022. Jack Bicer, director of vulnerability research at Action1, said the vulnerability can be exploited by a locally authenticated attacker to disclose information, defeat address space layout randomization (ASLR), and other defenses. "Vulnerabilities of this nature are commonly used to undermine Address Space Layout Randomization (ASLR), a core operating system security control designed to protect against buffer overflows and other memory-manipulation exploits," Kev Breen, senior director of cyber threat research at Immersive, told The Hacker News. "By revealing where code resides in memory, this vulnerability can be chained with a separate code execution flaw, transforming a complex and unreliable exploit into a practical and repeatable attack." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the latest fixes by February 3, 2026. Another vulnerability of note concerns a security feature bypass impacting Secure Boot Certificate Expiration (CVE-2026-21265, CVSS score: 6.4) that could allow an attacker to undermine a crucial security mechanism that ensures that firmware modules come from a trusted source and prevent malware from being run during the boot process. In November 2025, Microsoft announced that it will be expiring three Windows Secure Boot certificates issued in 2011, effective June 2026, urging customers to update to their 2023 counterparts - Microsoft Corporation KEK CA 2011 (June 2026) - Microsoft Corporation KEK 2K CA 2023 (for signing updates to DB and DBX) Microsoft Windows Production PCA 2011 (October 2026) - Windows UEFI CA 2023 (for signing the Windows boot loader) Microsoft UEFI CA 2011 (June 2026) - Microsoft UEFI CA 2023 (for signing third-party boot loaders) and Microsoft Option ROM UEFI CA 2023 (for signing third-party option ROMs) "Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time," Microsoft said. "To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance." The Windows maker also pointed out that the latest update removes Agere Soft Modem drivers "agrsm64.sys" and "agrsm.sys" that were shipped natively with the operating system. The third-party drivers are susceptible to a two-year-old local privilege escalation flaw (CVE-2023-31096, CVSS score: 7.8) that could allow an attacker to gain SYSTEM permissions. In October 2025, Microsoft took steps to remove another Agere Modem driver called "ltmdm64.sys" following in-the-wild exploitation of a privilege escalation vulnerability (CVE-2025-24990, CVSS score: 7.8) that could permit an attacker to gain administrative privileges. Also high on the priority list should be CVE-2026-20876 (CVSS score: 6.7), a critical-rated privilege escalation flaw in Windows Virtualization-Based Security (VBS) Enclave, enabling an attacker to obtain Virtual Trust Level 2 (VTL2) privileges, and leverage it to subvert security controls, establish deep persistence, and evade detection. "It breaks the security boundary designed to protect Windows itself, allowing attackers to climb into one of the most trusted execution layers of the system," Mike Walters, president and co-founder of Action1, said. "Although exploitation requires high privileges, the impact is severe because it compromises virtualization-based security itself. Attackers who already have a foothold could use this flaw to defeat advanced defenses, making prompt patching essential to maintain trust in Windows security boundaries." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors since the start of the month to rectify several vulnerabilities, including — ABB Adobe Amazon Web Services AMD Arm ASUS Broadcom (including VMware) Cisco ConnectWise Dassault Systèmes D-Link Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Imagination Technologies Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR n8n NETGEAR Node.js NVIDIA ownCloud QNAP Qualcomm Ricoh Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Sophos Spring Framework Synology TP-Link Trend Micro, and Veeam
thehackernews.comJan 14, 2026extracted
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days
Microsoft closed out 2025 with patches for 56 security flaws in various products across the Windows platform, including one vulnerability that has been actively exploited in the wild. Of the 56 flaws, three are rated Critical, and 53 are rated Important in severity. Two other defects are listed as publicly known at the time of the release. These include 29 privilege escalation, 18 remote code execution, four information disclosure, three denial-of-service, and two spoofing vulnerabilities. In total, Microsoft has addressed a total of 1,275 CVEs in 2025, according to data compiled by Fortra. Tenable's Satnam Narang said 2025 also marks the second consecutive year where the Windows maker has patched over 1,000 CVEs. It's the third time it has done so since Patch Tuesday's inception. The update is in addition to 17 shortcomings the tech giant patched in its Chromium-based Edge browser since the release of the November 2025 Patch Tuesday update. This also consists of a spoofing vulnerability in Edge for iOS (CVE-2025-62223, CVSS score: 4.3). The vulnerability that has come under active exploitation is CVE-2025-62221 (CVSS score: 7.8), a use-after-free in Windows Cloud Files Mini Filter Driver that could allow an authorized attacker to elevate privileges locally and obtain SYSTEM permissions. "File system filter drivers, aka minifilters, attach to the system software stack, and intercept requests targeted at a file system, and extend or replace the functionality provided by the original target," Adam Barnett, lead software engineer at Rapid7, said in a statement. "Typical use cases include data encryption, automated backup, on-the-fly compression, and cloud storage." "The Cloud Files minifilter is used by OneDrive, Google Drive, iCloud, and others, although as a core Windows component, it would still be present on a system where none of those apps were installed." It's currently not known how the vulnerability is being abused in the wild and in what context, but successful exploitation requires an attacker to obtain access to a susceptible system through some other means. Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have been credited with discovering and reporting the flaw. According to Mike Walters, president and co-founder of Action1, a threat actor could gain low-privileged access through methods like phishing, web browser exploits, or another known remote code execution flaw, and then chain it with CVE-2025-62221 to seize control of the host. Armed with this access, the attacker could deploy kernel components or abuse signed drivers to evade defenses and maintain persistence, and can be weaponized to achieve a domain-wide compromise when coupled with credential theft scenarios. The exploitation of CVE-2025-62221 has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to the Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to apply the patch by December 30, 2025. The remaining two zero-days are listed below - CVE-2025-54100 (CVSS score: 7.8) - A command injection vulnerability in Windows PowerShell that allows an unauthorized attacker to execute code locally CVE-2025-64671 (CVSS score: 8.4) - A command injection vulnerability in GitHub Copilot for JetBrains that allows an unauthorized attacker to execute code locally "This is a command injection flaw in how Windows PowerShell processes web content," Action1's Alex Vovk said about CVE-2025-54100. "It lets an unauthenticated attacker execute arbitrary code in the security context of a user who runs a crafted PowerShell command, such as Invoke-WebRequest." "The threat becomes significant when this vulnerability is combined with common attack patterns. For example, an attacker can use social engineering to persuade a user or admin to run a PowerShell snippet using Invoke-WebRequest, allowing a remote server to return crafted content that triggers the parsing flaw and leads to code execution and implant deployment." It's worth noting that CVE-2025-64671 comes in the wake of a broader set of security vulnerabilities collectively named IDEsaster that was recently disclosed by security researcher Ari Marzouk. The issues arise as a result of adding agentic capabilities to an integrated development environment (IDE), exposing new security risks in the process. These attacks leverage prompt injections against the artificial intelligence (AI) agents embedded into IDEs and combine them with the base IDE layer to result in information disclosure or command execution. "This uses an 'old' attack chain of using a vulnerable tool, so not exactly part of the IDEsaster novel attack chain," Marzouk, who is credited with discovering and reporting the flaw, told The Hacker News. "Specifically, a vulnerable 'execute command' tool where you can bypass the user-configured allow list." Marzouk also said multiple IDEs were found vulnerable to the same attack, including Kiro.dev, Cursor (CVE-2025-54131), JetBrains Junie (CVE-2025-59458), Gemini CLI, Windsurf, and Roo Code (CVE-2025-54377, CVE-2025-57771, and CVE-2025-65946). Furthermore, GitHub Copilot for Visual Studio Code has been found to be susceptible to the vulnerability, although, in this case, Microsoft assigned it a "Medium" severity rating with no CVE. "The vulnerability states that it's possible to gain code execution on affected hosts by tricking the LLM into running commands that bypass the guardrails and appending instructions in the user's 'auto-approve' settings," Kev Breen, senior director of cyber threat research at Immersive, said. "This can be achieved through 'Cross Prompt Injection,' which is where the prompt is modified not by the user but by the LLM agents as they craft their own prompts based on the content of files or data retrieved from a Model Context Protocol (MCP) server that has risen in popularity with agent-based LLMs." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify multiple vulnerabilities, including — Adobe Amazon Web Services AMD Arm ASUS Atlassian Bosch Broadcom (including VMware) Canon Cisco Citrix CODESYS Dell Devolutions Django Drupal F5 Fortinet Fortra GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Imagination Technologies Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR NVIDIA OPPO Progress Software Qualcomm React Rockwell Automation Samsung SAP Schneider Electric Siemens SolarWinds Splunk Synology TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comDec 10, 2025extracted
In Other News: Deepwatch Layoffs, macOS Vulnerability, Amazon AI Bug Bounty
SecurityWeek’s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar. We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape. Each week, we curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports. Here are this week’s stories: Russian man pleads guilty over Yanluowang ransomware attacks Aleksei Olegovich Volkov, a 25-year-old Russian national, has pleaded guilty to charges related to his role as an initial access broker for the Yanluowang ransomware group in 2021 and 2022, CyberScoop reported. Prosecutors said two of the group’s victims paid a total of $1.5 million in ransoms. Volkov was arrested in Italy in 2024 and extradited to the United States, where he faces up to 53 years in prison. Asahi brewer’s supply crippled by ransomware one month after attack Japan’s largest brewer, Asahi, continues to suffer severe disruption to its domestic order and logistics systems more than a month after a ransomware attack by the Qilin group. The incident forced the company to revert to manual processing, cutting beer shipments to approximately 10% of regular volumes during Japan’s peak season, The Japan Times reported. The prolonged disruption has allowed competitors to gain market share. Synology patches vulnerability disclosed at Pwn2Own Synology released a patch for a critical remote code execution vulnerability in its BeeStation OS that was successfully demonstrated at the Pwn2Own Ireland 2025 competition. The flaw is identified as CVE-2025-12686. Researchers from Synacktiv were awarded $40,000 for discovering and exploiting the issue. QNAP has also released patches for flaws disclosed at Pwn2Own. Amazon starts private AI bug bounty program Amazon has launched a new private AI bug bounty program to strengthen its foundation models, including Amazon Nova. The invite-only program aims to engage security researchers and university experts to find and fix security vulnerabilities, biases, and potential for harmful activities like prompt injection and CBRN (Chemical, Biological, Radiological, and Nuclear) threat assistance. This initiative complements Amazon’s existing public bug bounty program and offers rewards ranging from $200 to $25,000. Windows Kerberos delegation flaw allows full domain control Silverfort discovered a new Windows Kerberos delegation vulnerability, tracked as CVE-2025-60704 and dubbed ‘CheckSum’, which affects any organization using Active Directory with delegation enabled. The flaw allows an attacker who has gained initial access to an environment to impersonate arbitrary users, escalate privileges, and ultimately gain control over the entire domain. Microsoft has issued an update as part of Patch Tuesday to address the vulnerability, which carries a CVSS score of 7.5. Researchers uncover Sora 2 system prompt Researchers from Mindgard successfully extracted the hidden system prompt (the core internal instructions) from OpenAI’s Sora 2 video generation model. The team accomplished this using a technique that involved asking the model to reveal its hidden instructions through text, image, video, and audio generation. While text and image-based attacks produced only fragments, audio generation (especially with transcripts enabled) allowed the researchers to stitch together a nearly complete system prompt. Deepwatch lays off staff to boost AI Cybersecurity firm Deepwatch has laid off between 60 and 80 employees, representing roughly a quarter of its total workforce, TechCrunch reported. CEO John DiLullo stated the restructuring is necessary to “accelerate our significant investments in AI and automation” and enhance the company’s technology capabilities. Apple fixes Compressor code execution flaw Apple released the Compressor 4.11.1 update for macOS Sequoia 15.6 and later to address a vulnerability (CVE-2025-43515) that could allow an unauthenticated user on the same network to execute arbitrary code. The security issue was mitigated by modifying the software to now refuse external connections by default. Google reports 1000x reduction in Android memory bugs with Rust Google’s Android team reported that using the Rust programming language has led to a 1000x reduction in the density of memory safety vulnerabilities compared to C and C++ code. The shift to Rust has made the secure development path faster, with Rust changes requiring 25% less time in code review and having a 4x lower rollback rate than C++. EchoGram attack undermines AI guardrails HiddenLayer researchers have uncovered EchoGram, a new attack technique that undermines common AI defense mechanisms like text classification and ‘LLM-as-a-judge’ guardrails. The exploit uses specific token sequences to manipulate the defensive model’s verdict, allowing malicious prompts to be approved or causing false alarms. This systemic vulnerability affects defenses used in major models like GPT-4, Gemini, and Claude.
securityweek.comNov 14, 2025extracted
Synology risolve un bug zero-day in BeeStation OS. 40.000 dollari ai ricercatori
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comNov 12, 2025extracted
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
Microsoft on Tuesday released patches for 63 new security vulnerabilities identified in its software, including one that has come under active exploitation in the wild. Of the 63 flaws, four are rated Critical and 59 are rated Important in severity. Twenty-nine of these vulnerabilities are related to privilege escalation, followed by 16 remote code execution, 11 information disclosure, three denial-of-service (DoS), two security feature bypass, and two spoofing bugs. The patches are in addition to the 27 vulnerabilities the Windows maker addressed in its Chromium-based Edge browser since the release of October 2025's Patch Tuesday update. The zero-day vulnerability that has been listed as exploited in Tuesday's update is CVE-2025-62215 (CVSS score: 7.0), a privilege escalation flaw in Windows Kernel. The Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) have been credited with discovering and reporting the issue. "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally," the company said in an advisory. That said, successful exploitation hinges on an attacker who has already gained a foothold on a system to win a race condition. Once this criterion is satisfied, it could permit the attacker to obtain SYSTEM privileges. "An attacker with low-privilege local access can run a specially crafted application that repeatedly attempts to trigger this race condition," Ben McCarthy, lead cybersecurity engineer at Immersive, said. "The goal is to get multiple threads to interact with a shared kernel resource in an unsynchronized way, confusing the kernel's memory management and causing it to free the same memory block twice. This successful 'double free' corrupts the kernel heap, allowing the attacker to overwrite memory and hijack the system's execution flow." It's currently not known how this vulnerability is being exploited and by whom, but it's assessed to be used as part of a post-exploitation activity to escalate their privileges after obtaining initial access through some other means, such as social engineering, phishing, or exploitation of another vulnerability, Satnam Narang, senior staff research engineer at Tenable, said. "When chained with other bugs this kernel race is critical: an RCE or sandbox escape can supply the local code execution needed to turn a remote attack into a SYSTEM takeover, and an initial low‑privilege foothold can be escalated to dump credentials and move laterally," Mike Walters, president and co-founder of Action1, said in a statement. Also patched as part of the updates are two heap-based buffer overflow flaws in Microsoft's Graphics Component (CVE-2025-60724, CVSS score: 9.8) and Windows Subsystem for Linux GUI (CVE-2025-62220, CVSS score: 8.8) that could result in remote code execution. Another vulnerability of note is a high-severity privilege escalation flaw in Windows Kerberos (CVE-2025-60704, CVSS score: 7.5) that takes advantage of a missing cryptographic step to gain administrator privileges. The vulnerability has been codenamed CheckSum by Silverfort. "The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications," Microsoft said. "An unauthorized attacker must wait for a user to initiate a connection." Silverfort researchers Eliran Partush and Dor Segal, who discovered the shortcoming, described it as a Kerberos constrained delegation vulnerability that allows an attacker to impersonate arbitrary users and gain control over an entire domain by means of an adversary-in-the-middle (AitM) attack. An attacker who is able to successfully exploit the flaw could escalate privileges and move laterally to other machines in an organization. More concerning, threat actors could also gain the ability to impersonate any user in the company, allowing them to gain unfettered access or become a domain administrator. "Any organization using Active Directory, with the Kerberos delegation capability turned on, is impacted," Silverfort said. "Because Kerberos delegation is a feature within Active Directory, an attacker requires initial access to an environment with compromised credentials." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — Adobe Amazon Web Services AMD Apple ASUS Atlassian AutomationDirect Bitdefender Broadcom (including VMware) Cisco Citrix ConnectWise D-Link Dell Devolutions Drupal Elastic F5 Fortinet GitLab Google Android Google Chrome Google Cloud Grafana Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Firefox ESR NVIDIA Oracle Palo Alto Networks QNAP Qualcomm Rockwell Automation Ruckus Wireless Samba Samsung SAP Schneider Electric Siemens SolarWinds SonicWall Splunk Spring Framework Supermicro Synology TP-Link WatchGuard, and Zoom
thehackernews.comNov 12, 2025extracted
Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland
Synology has addressed a critical-severity remote code execution (RCE) vulnerability in BeeStation products that was demonstrated at the recent Pwn2Own hacking competition. The security issue (CVE-2025-12686) is described as a ‘buffer copy without checking the size of input’ problem, and can be exploited to allow arbitrary code execution. It impacts multiple versions of BeeStation OS, the software powering Synology’s network-attached storage (NAS) devices marketed as a consumer-oriented “personal cloud.” There are no mitigations available, so the vendor recommends that users upgrade to the following versions, which address : BeeStation OS version 1.3.2-65648 or above BeeStation OS version 1.3.2-65648 or above BeeStation OS version 1.3.2-65648 or above BeeStation OS version 1.3.2-65648 or above Researchers Tek and anyfun at French cybersecurity company Synacktiv exploited the flaw in a demonstration during the Pwn2Own Ireland 2025 contest on October 21st. For their successful exploitation, the two researchers received a $40,000 reward. A three-day hacking competition organized by Trend Micro and the Zero Day Initiative (ZDI), Pwn2Own gives security researchers the opportunity to hack popular consumer devices using zero-day vulnerabilities. The most recent event held in Ireland had researchers demonstrating 73 zero-day flaws across a broad range of products and winning more than $1 million. Last week, another major NAS vendor, QNAP, fixed a total of seven zero-day vulnerabilities in multiple devices from the company, which white-hat hackers had shown at Pwn2Own Ireland this year. ZDI has a disclosure agreement with companies participating in Pwn2Own and holds off publishing the technical details of the security issues until patches are available and users have had sufficient time to apply the updates. More details about these flaws will be disclosed in the coming months on ZDI’s bulletin board and, in some cases, on personal blog spaces of the researchers themselves. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 11, 2025extracted
Pwn2Own WhatsApp Hacker Says Exploit Privately Disclosed to Meta
A total of $1,024,750 has been paid out at the Pwn2Own Ireland 2025 hacking contest organized by Trend Micro’s Zero Day Initiative (ZDI), but the event has been overshadowed by the last-minute withdrawal of a researcher who was scheduled to demonstrate a WhatsApp exploit worth $1 million. The highest reward at Pwn2Own Ireland 2025, $100,000, was paid out for an exploit chain targeting the QNAP Qhora-322 router and the QNAP TS-453E NAS device. Two Samsung Galaxy S25 exploit chains were each rewarded with $50,000, and the same amount was earned for vulnerabilities in Synology ActiveProtect Appliance DP320 and the Sonos Era 300 smart speaker. Participants received up to $40,000 for hacking Ubiquiti cameras, QNAP and Synology NAS devices, Lexmark and Canon printers, and smart home systems such as Phillips Hue Bridge, Amazon Smart Plug, and Home Automation Green. A total of 73 previously unknown vulnerabilities were disclosed at Pwn2Own Ireland 2025. A researcher named Eugene (3ugen3) of Team Z3 was scheduled to demonstrate a $1 million zero-click remote code execution exploit against WhatsApp on Thursday. However, the demonstration did not take place. ZDI initially said there was a delay due to “travel complications and delayed flights”, but noted that the researcher would still submit his exploit. ZDI later announced that the researcher withdrew from the competition, citing concerns that the exploit was not sufficiently prepared for a public demonstration. “Team Z3 has withdrawn their WhatsApp entry from Pwn2Own as they did not feel their research was ready to publicly demonstrate,” said Dustin Childs, head of threat awareness at ZDI. “However, Meta remains interested in receiving this research. Team Z3 is disclosing their findings to ZDI analysts to do an initial assessment before handing it over to Meta engineers,” Childs added. “While we are disappointed that we don’t get to publicly show the demo on the Pwn2Own stage, we’re happy to facilitate the coordinated disclosure to Meta so they have the opportunity to address issues should they prove valid.” No updates have been shared on ZDI’s assessment, whether any zero-day exploit information has been shared with Meta, and whether the social media giant paid any bounty for the WhatsApp hack. The delay, the withdrawal, and the lack of public disclosure has led to wide-ranging disappointment and speculation within the security industry regarding the technical viability of the purported exploit. Contacted by SecurityWeek, Eugene, who appears to be from China, described Pwn2Own as an “amazing event”. The researcher said, “We decided to keep everything private between Meta, ZDI and myself. No comments,” adding that he did not want his true identity revealed to the public. Eugene told SecurityWeek that he signed an NDA that prevents him from sharing any details. SecurityWeek has also reached out for comment to ZDI and WhatsApp and will update this article if they respond. UPDATE: A WhatsApp spokesperson has provided the following statement to SecurityWeek. A follow-up article with additional information is available here. “We’re disappointed that Team Z3 withdrew from Pwn2Own yesterday because they didn’t have a viable exploit, but we were in contact with ZDI and Team Z3 to understand their research so we can triage the low-risk bugs we received. As always, we stand ready to receive valid research from the community through our bug bounty program and are grateful to security researchers and Pwn2Own for ongoing collaboration.” Related: $4.5 Million Offered in New Cloud Hacking Competition Related: Over $3 Million in Prizes Offered at Pwn2Own Automotive 2026 Related: VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched
securityweek.comOct 24, 2025extracted
Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland
The Pwn2Own Ireland 2025 hacking competition has ended with security researchers collecting $1,024,750 in cash awards after exploiting 73 zero-day vulnerabilities. At Pwn2Own Ireland 2025, competitors targeted products in eight categories, including printers, network storage systems, messaging apps, smart home devices, surveillance equipment, home networking equipment, flagship smartphones (Apple iPhone 16, Samsung Galaxy S25, and Google Pixel 9), and wearable technology (including Meta's Ray-Ban Smart Glasses and Quest 3/3S headsets). This year's contest also expanded the attack surface to include USB port exploitation on mobile handsets, requiring researchers to hack locked devices via a physical connection. However, traditional wireless protocols like Bluetooth, Wi-Fi, and NFC (near-field communication) remained valid attack vectors. The hacking contest, co-sponsored by Meta alongside QNAP and Synology, took place from October 21 to October 23 in Cork, Ireland. Summoning Team won this year's edition of Pwn2Own Ireland with 22 Master of Pwn points and $187,500 earned throughout the three-day event after hacking the Samsung Galaxy S25, the Synology DiskStation DS925+ NAS, the Home Assistant Green, the Synology ActiveProtect Appliance DP320 NAS drive, the Synology CC400W camera, and the QNAP TS-453E NAS device. Team ANHTUD secured the second position with $76,750 and 11.5 Master of Pwn points, while Team Synactiv took third place with $90,000 in prizes and 11 Master of Pwn points. On the first day of Pwn2Own Ireland, hackers exploited 34 unique zero-days and collected $522,500 in cash awards. On the second day of the event, they demoed another 22 unique zero-day vulnerabilities for $267.500. The highlight of the last day was the Samsung Galaxy S25 getting hacked by Interrupt Labs' team via an improper input validation bug, who earned 5 Master of Pwn points and $50,000 after also enabling location tracking and the camera in the process. While Team Z3 was also scheduled today to demonstrate a WhatsApp Zero-Click remote code execution zero-day, eligible for a $1 million reward, they withdrew from the competition. They chose to disclose their findings privately to ZDI analysts before sharing their research with Meta's engineering team. The Zero Day Initiative (ZDI) organizes this hacking contest to identify security vulnerabilities before threat actors can exploit them in attacks and coordinate responsible disclosure with the affected vendors. After the zero-days are exploited at Pwn2Own, the vendors have 90 days to release patches before Trend Micro's Zero Day Initiative publicly discloses them. In January 2026, the ZDI will once again be at the Automotive World technology show in Tokyo, Japan, for the third Pwn2Own Automotive contest, again sponsored by Tesla Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 24, 2025extracted
Loading 11 more…