Search/watchguard
Vendor

watchguard

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
hawkeye g
Connections
118 relationships
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks. This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3. When it released CVE-2025-14733 security patches in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured. WatchGuard also confirmed that attackers were Internet security watchdog group Shadowserver found over 115,00 unpatched Firebox firewalls exposed online in December, and nearly 9,000 instances remain unsecured after nine months. In a Thursday update to its catalog of actively exploited vulnerabilities, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said the CVE-2025-14733 flaw is now known to be used by ransomware gangs but has not provided more details about their attacks. CISA first added the flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, when it ordered U.S. federal agencies to secure their systems within a week, as mandated by Binding Operational Directive (BOD) 22-01. Two years ago, the cybersecurity agency ordered government agencies to patch another actively exploited WatchGuard flaw (CVE-2022-23176) affecting Firebox and XTM firewalls. More recently, in September 2025, WatchGuard patched almost identical to CVE-2025-14733. One month later, Shadowserver found more than 75,000 Firebox firewalls vulnerable to attacks. WatchGuard provides services to more than 250,000 small and mid-sized companies through a network of more than 17,000 security resellers and service providers worldwide. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat
bleepingcomputer.comSep 10, 2026extracted
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. ⚡ Threat of the Week N-able Patches Critical N-central Flaws — N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Also patched is a maximum-severity security flaw (CVE-2026-86218, CVSS score: 10.0) that could allow for pre-authenticated remote code execution on the N-central server. "At this time, we have no confirmation that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk," N-able said. However, Huntress said it observed signs that attackers are likely leveraging CVE-2026-86206 or/and CVE-2026-86207, after it launched an investigation on September 4 following the compromise of a customer's fully patched N-central production environment. "However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," it said. AI Spend Out of Control? There's a Path Forward Imagine you’ve received a water bill for 500,000,000 gallons. Now, you have to account for every teaspoon of that water. IT leaders face a similar task when managing AI budgets, and it’s not as simple as token caps or model limits. Learn how your team can optimize your company's AI spend. Learn More ➝ 🔔 Top News Google Warns of Chrome 0-Day Under Attack — Google released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," according to a description of the flaw in CVE.org. Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks or who is behind them. With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. MikroTik RouterOS Flaws Exploited — The CERT Polska Team warned that bad actors are actively exploiting two zero-day flaws in MikroTik RouterOS that could be combined to take full control of the device without authentication if the device supports remote access using the SSH protocol. The exploit chain has been codenamed MikroTrick. A total of fix flaws (CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060) have been identified. The MikroTrick chain involves CVE-2026-67276 and CVE-2026-86060 (CVSS scores: 9.2), which can allow an attacker to bypass authentication and elevate their privileges. The issues have been fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). "The successful attacks observed so far, including the creation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpatched Magento and Adobe Commerce 0-Day Exploited to Backdoor Online Stores — E-commerce storefronts are being compromised to inject a backdoor by exploiting an unpatched Magento and Adobe Commerce zero-day dubbed StyleSmuggler, which gives unauthenticated attackers remote code execution. The attacks commenced on September 4, 2026. "StyleSmuggler injects malicious code into Magento's template system," Sansec said. "By using the styles properties, it can evade existing safeguards. It works in two stages: (1) Inject (poison) PHP code, for example by generating a failure report, and (2) Let Magento execute the poisoned code via a failed payment email." The backdoor is a Rust program that connects to the "99.84.67[.]186" C2 server and waits for further instructions. There are currently no indications that the backdoor has been weaponized. There are two different variants named fc-cache and chronyd. A separate attack cluster has been found to leverage the same weakness to drop a PHP web shell into the product image cache. RevStealer Spreads via Game Cheats and Fake Claude Desktop App — Elastic and Morphisec disclosed details of RevStealer (aka REF2859), a Windows information stealer that comes with an embedded sandbox scoring system and Polygon blockchain-based dead drop for resilience, a technique also called EtherHiding. "Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets," Elastic said. The malware is distributed via social engineering attacks, using YouTube videos claiming to advertise hacks for the Albion Online game or rogue GitHub repositories for Anthropic's Claude Opus 5 Free Desktop project. Once installed, the stealer can receive additional executable content through C2 tasks, including additional executable content through (for wallet-file and browser-extension theft, phishing overlays, password-aware input capture, and payload delivery), WinUpdate (for cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (for reverse SOCKS5 proxy and backconnect access over an encrypted WebSocket protocol), and LockAppHost (for XMRig deployment, competitor suspension, and persistence). OpenAI Agents Keep Going Rogue — OpenAI is once again in hot water after a swarm of agents self-identifying as from the AI startup hijacked a German website as early as May and used it as a bulletin board for other AI agents. The agent swarm is said to have taken over the obscure German-language wiki in May and June to make around 18,000 posts, relying on it to coordinate on evaluations and swap methods to evade OpenAI’s own controls. The revelations come days after OpenAI published its own detailed account of July's Hugging Face breach in which another swarm of OpenAI agents worked together to escape their sandbox during a cybersecurity evaluation and break into Hugging Face's servers. A subsequent cluster used similar techniques to break into OpenAI's own infrastructure. In response to the wiki incident, OpenAI said it is working on a framework for reporting misalignment incidents during training, evaluation, and deployment. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-78174, CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-57910, CVE-2026-57909, CVE-2026-13086 (WatchGuard), CVE-2026-80047 (Hugging Face Transformers), CVE-2026-9585, CVE-2026-9586, CVE-2026-9587, CVE-2026-9588 (Sangoma Switchvox SMB), CVE-2026-6881 (Ellucian Advance Web and Legacy Advance), CVE-2026-13381, CVE-2026-13380 (VSee Clinic), CVE-2026-63219, CVE-2026-58400 (GeoNetwork), CVE-2026-9637, CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-19471, CVE-2026-19472, CVE-2026-12663, CVE-2026-9633, CVE-2026-9634, CVE-2026-16675, CVE-2025-12768, CVE-2026-84235 (Rockwell Automation), CVE-2026-84115 (Cleo Harmony), CVE-2026-84117, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84126 (Mozilla Firefox), CVE-2026-84353, CVE-2026-84352, CVE-2026-85046 (Google Chrome), CVE-2026-19949 (All-in-One WP Migration and Backup), CVE-2026-20277, CVE-2026-20278, CVE-2026-20280, CVE-2026-20279, CVE-2026-20276, CVE-2026-20275, CVE-2026-20274, CVE-2026-20212 (Cisco), CVE-2026-15630 (Casdoor), CVE-2026-73749 (Hewlett Packard Enterprise ArubaOS-CX), CVE-2026-67394 (Plesk), CVE-2026-38577 (Tenda), CVE-2026-6471 aka PostGREShell (PostgreSQL), CVE-2026-42038 (Axios), CVE-2026-64532, CVE-2026-64533 (Linux Kernel), CVE-2026-58048 (cPanel and WHM), CVE-2026-14540 (Google mcp-toolbox), CVE-2026-84645, CVE-2026-84647, CVE-2026-84648, CVE-2026-84649, CVE-2026-84650, CVE-2026-84652, CVE-2026-84665, CVE-2026-84667, CVE-2026-84668, CVE-2026-84669, CVE-2026-84670, CVE-2026-84671, CVE-2026-84672, CVE-2026-84673 (Jenkins), GHSA-x7v6-xfx3-52j6, GHSA-r7jx-j9h7-j4xj, GHSA-9jcm-x588-gh26, GHSA-6mpx-c8rj-whj5, GHSA-q65v-4w7q-hx3r (FreeRDP), CVE-2026-59346, CVE-2026-59347 (Broadcom VMware Workstation and Fusion), CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060 (MikroTik RouterOS), CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190 (Telerik UI for ASP.NET AJAX), CVE-2026-86218, CVE-2026-86206, and CVE-2026-86207 (N-able N-central). 🎥 Cybersecurity Webinars A New Vulnerability Drops. Learn How to Find Out ”If You’re Exposed” Faster → Your security tools have the data. Getting an answer shouldn’t take days. See how Tines brings software, cloud, application, and vulnerability data into one dashboard—and learn how to give your team a faster, clearer view of what’s at risk. Find Which Vulnerabilities Attackers Can Actually Exploit—in Hours, Not Weeks → A vulnerability alert doesn’t tell you whether an attacker can break in. Learn how to test exploitability with real-world attack simulations, identify the gaps that matter, and focus remediation on proven risks—not just severity scores. 📰 Around the Cyber World New Knight Office Microsoft 365 AitM Phishing Kit — A new adversary-in-the-middle (AiTM) phishing toolkit called Knight Office has been spotted in the wild using Docusign-themed lures to direct victims to fake landing pages for AitM token theft and device code phishing attacks, joining the likes of EvilTokens and Kali365. The email "led the victim through a number of redirects (including a redirect via the Monday work management platform and a compromised Joomla website)," Huntress said. "The victim landed on a phishing page, where their valid session tokens were captured and fed to the Knight Office console. Session tokens allow attackers to access victim accounts as if they were logged in, without needing an actual password or a way to bypass multi-factor authentication (MFA)." At least nine total phishing attacks on identities have been linked to this kit over the past two weeks. The Blind Spot in SNMPv3 — SNMPv3 — the protocol widely regarded as the secure standard for managing routers, switches, and firewalls — leaks pre-authentication signals that can allow an unauthenticated remote actor to identify a device’s vendor, confirm valid usernames, and narrow its likely encryption settings before testing a single credential. Validated across approximately 470,000 internet-exposed endpoints, the findings show how these standards-compliant behaviors can collapse a multi-dimensional brute-force problem into a focused password-guessing exercise. "SNMPv3 was the industry's answer to insecure network management, and upgrading to it — as the CISA advisory urges — is necessary," said Kobi Ben-Naim, Co-Founder and CEO of Malanta. "But that answer is incomplete. The protocol does exactly what it was designed to do, and that design hands attackers a roadmap: even properly upgraded deployments, when exposed, leak enough through pre-authentication responses to help an attacker narrow their way in before a single credential is tested. The threat doesn't end with the upgrade." U.S. Announces Reward for Senior Iranian Official — A $10 million reward has been posted by the U.S. State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps' (IRGC) Cyber-Electronic Command (CEC). "Yaryab also oversees and controls operations conducted by IRGC-CEC-affiliated groups such as CyberAv3ngers, Dadeh Afzar Arman (DAA), and Mehrsam Andisheh Saz Nik (MASN). These malicious cyber groups have used malware to target civilian infrastructure worldwide," the State Department said. Attack on Coder — Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code to harvest environment variables, API keys, CI/CD credentials, configuration secrets, terminal history, OIDC tokens, SSH keys, external authentication tokens, and Coder database passwords. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry," Coder said. "These unauthorized IP addresses hosted a version of Coder's registry that contained artifacts which included malicious code." Users are advised to look for connections to the malicious domains before applying the latest patches (versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9) U.S.-U.K. Team Up to Shut Down Scam Centers — The U.S. and the U.K. signed a Memorandum of Understanding (MoU) to work together on an initiative to shut down scam centers stealing billions of dollars through investment and romance fraud schemes. "Under the terms of the MOU, each will conduct parallel investigations into common targets, share information on targeting of organized crime syndicates, discuss which jurisdictions to bring specific cases of common interest, and generally prioritize cases on this threat to achieve mutual results," the U.S. Justice Department said. Tampered Exodus Installer Delivers Modular RAT — Victims are being tricked into running a fake PDF document or a software update that leads to the execution of an MSI installer that declares itself a "Background Service" by Apple. "The 'Background Service' installs a genuine Exodus 24.33.4 cryptocurrency wallet, missing one key function: any way for the user to interact with it," Huntress said. "Only 3 of its 1,973 files differ from the real thing. One of those three files stops the wallet from ever drawing a window. Another turns a legitimate Exodus source file into a PE loader that decrypts a 10 MB payload and maps it into memory by hand, where it never touches disk. That payload is the RAT: a hidden VNC and SOCKS proxy that enable remote access and browser credential theft. While the RAT stealthily beacons to Azure Table Storage rather than a domain of its own, it returns every hour through a scheduled task, leaving behind detectable artifacts." QR Phishing With No Image — In a new phishing attack detailed by Kaspersky, threat actors are building a QR code out of text characters and markup directly in the email body as opposed to rendering an image. "There is no attachment to open, no embedded picture to decode, and nothing for an image-based or optical-character-recognition (OCR) scanner to key off," PhishU said. "Because it is markup and not a remote image, an inbox with images turned off still paints it. The message shows a perfectly scannable QR to the human reading it, image-blocking and all." Apple Hit With $2.7 Billion Lawsuit Over App Tracking Rules — Apple is facing a £2 billion ($2.7 billion) lawsuit in the U.K. accusing it of imposing stricter App Tracking Transparency rules on third-party developers than on its own advertising services, thereby giving its ecosystem a competitive advantage, according to Reuters. Apple's App Tracking Transparency feature has been the subject of extensive investigations across Europe. Last month, Apple agreed to make changes to the feature across almost all European Union countries following a probe in Germany. Attackers Routinely Target Edge Devices — A joint analysis from SentinelOne and Tenable found that both nation-state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs. "Both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure," the companies said. "The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch." The disclosure comes as current attacker timelines are compressing and moving faster than standard patch cycles can address, driven by frontier AI models that narrow the window between vulnerability discovery and exploitation. The Threat of Indirect Prompt Injection — New research from Forcepoint revealed that an email summarizer running an unguarded LLM pipeline can be manipulated through indirect prompt injection (i.e., hidden instructions in an email) to silently hijack summarizer output and generate false and potentially dangerous summaries without signaling tampering to the recipient. It's the latest example of how attackers can use indirect prompt injections to undermine AI systems and get them to behave in unintended ways when processing external content. It's also a reminder of AI's fundamental limitations. Large language models (LLMs) cannot distinguish between authentic user instructions entered directly into a prompt and content they find on untrusted third-party sources, leading to prompt injections. "A regular Outlook email composer does strip styling that hides elements on copy/paste and does not provide any way to hide text other than white text on white background," Forcepoint said. "The hidden styling was not stripped when sent programmatically, or when the message is received and displayed. Hidden HTML tags like these have been commonly used by attackers to circumvent careful reading by victims." Conclusion Trusted sources and safer settings still have limits. This week’s attacks show why it matters to know exactly what each protection covers—and what it leaves exposed. Keep patching, but keep the logs needed to investigate, too. “Fully patched” tells you which fixes are installed. It doesn’t prove nobody got in.
thehackernews.comSep 7, 2026extracted
Chrome and Firefox Updates Patch Dozens of Vulnerabilities
Google and Mozilla on Tuesday announced patches for dozens of vulnerabilities across Chrome and Firefox, including critical- and high-severity flaws. A fresh Chrome 152 update has been rolled out with fixes for 26 bugs, two of which are critical-severity use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352). The update also addresses nine high-severity security defects, including use-after-free, incorrect authorization, information leak, improper input validation, uninitialized resource, and buffer overflow weaknesses. The remaining 15 vulnerabilities are medium- and low-severity issues. Per Google’s advisory, only three of the flaws were reported by external researchers, but no bug bounty reward has been disclosed. The latest Chrome iteration is now rolling out as versions 152.0.7977.75/.76 for Windows and macOS, and as version 152.0.7977.75 for Linux. Mozilla rolled out Firefox 155 with patches for 29 security defects, including 13 high-severity use-after-free, sandbox escape, and memory corruption issues. The flaws were addressed in Firefox’s GC, Navigation, Audio/Video, Security, WebGPU, Core & HTML, and Grid components, and in Firefox for Android. Three of the issued CVEs cover multiple bugs leading to memory corruption that could have been potentially exploited “with enough effort”. On Tuesday, Mozilla also announced the release of Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2 with fixes for these vulnerabilities. Google and Mozilla make no mention of any of these vulnerabilities being exploited in the wild. Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Related: Hackers Start Exploiting Critical Langflow Vulnerability Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild Related: WatchGuard Patches Critical Vulnerabilities
securityweek.comSep 2, 2026extracted
Hackers Start Exploiting Critical Langflow Vulnerability
Threat actors have started exploiting a critical-severity remote code execution (RCE) vulnerability in the AI low-code platform Langflow, vulnerability intelligence firm VulnCheck warns. Tracked as CVE-2026-0768 (CVSS score of 9.8), the security defect exists within the code validator in Langflow’s custom component editor. Because a user-supplied string is not properly validated before it is used for Python code execution, an attacker could exploit the bug to execute arbitrary code as root without authentication. The security flaw was reported through ZDI in July 2025 and was publicly disclosed as a zero-day in January 2026. All Langflow releases up to version 1.4.2 are affected. According to VulnCheck, threat actors have been exploiting the vulnerability to perform reconnaissance and credential harvesting operations. The cybersecurity firm observed queries for environment variables, secret keys, and SSH access, mainly originating from Russia. By Monday, VulnCheck had seen over 360 exploitation attempts hitting its canaries in the UK. CVE-2026-0768’s in-the-wild exploitation does not come as a surprise. Last week, VulnCheck warned of a recently observed increase in Langflow vulnerability targeting. “Before 2026, evidence showed only one Langflow vulnerability known to be exploited in the wild. In 2026, things have changed fast. We’ve now seen 11 additional vulnerabilities targeted and reported as exploited in the wild, highlighting increasing attacker interest in Langflow,” the company said. VulnCheck has seen more than 15,000 attacks successfully exploiting Langflow instances vulnerable to three of the known exploited flaws, namely CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027. Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild Related: WatchGuard Patches Critical Vulnerabilities Related: PaperCut Exploitation Escalates to Active Intrusions Related: Silent Patches Don’t Stop Attackers – They Blind Defenders
securityweek.comSep 1, 2026extracted
WatchGuard Patches Critical Vulnerabilities
WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover. Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols. Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315). Attackers could send specially crafted network traffic to trigger each of these vulnerabilities and achieve RCE, WatchGuard says. WatchGuard also patched a critical stack-based buffer overflow bug (CVE-2026-13086) in the Endpoint Protection Manager (epm) service that is used by the deprecated Mobile Security feature in Fireware OS, which could lead to RCE. Additionally, the company fixed CVE-2026-78174 in WatchGuard Dimension, which could allow low-privileged administrators to extract a super admin’s session ID and CSRF tokens and take over their account. All five security defects have a CVSS score of 9.3. Fixes for them were included in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, and Dimension version 2.3.1. The updates also resolve seven high-severity Fireware OS vulnerabilities that could lead to denial-of-service (DoS), including six impacting the iked process, and five high-severity Dimension bugs leading to arbitrary command execution, tampering with the global administrator’s passphrase, and DoS. Patches were also rolled out for 11 medium-severity vulnerabilities, including one in Fireware OS’s iked process and 10 in Dimension. WatchGuard says it is not aware of any of these security defects being exploited in the wild. Additional information can be found on the company’s security advisories page. Related: PaperCut Exploitation Escalates to Active Intrusions Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Related: ServiceNow Patches 3 Critical Code Injection Vulnerabilities Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
securityweek.comSep 1, 2026extracted
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs much decoration. The small gaps are doing enough work already. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Signed driver abuseIn new research, Check Point has reverse engineered Microsoft Defender's Defender Boot-Time Removal driver ("BTR.sys") and demonstrated that it's possible to repurpose the signed remediation driver as a universal kernel operation engine to bypass endpoint security solutions by exploiting a "golden window" between system start and user mode initialization without having to rely on the bring your own vulnerable driver (BYOVD) method. "Because BTR.sys is a legitimate Microsoft-signed component, signature-based blocking is ineffective," security researcher Jiří Vinopal said. "Furthermore, a well-crafted weaponization tool (like BTR_CLI) intentionally mimics the operational footprint of the legitimate Windows Defender remediation process." $10 million rewardThe U.S. Department of Justice (DoJ) has charged 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute has been accused of stealing more than 31 TB of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs. In all, the Mabna Institute targeted more than 100,000 accounts of professors around the world, successfully compromising approximately 8,000 of them. The defendants carried out these intrusions on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). The Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi around 2013. "The campaign started in approximately 2013, continued through at least December 2017, and broadly targeted all types of academic data and intellectual property from the systems of compromised universities," the DoJ said. "In addition to stealing academic data and login credentials for the benefit of the Government of Iran, the defendants also sold the stolen data through two websites, Megapaper.ir (Megapaper) and Gigapaper.ir (Gigapaper)." The U.S. Department of State is offering a $10 million reward for information about five of the defendants, or associated individuals or entities. "Mabna represents the privatization of state espionage: a contractor selling stolen research to whoever's paying, with the IRGC as an anchor client rather than a sole owner," Shmuel Gihon, Security Research Team Lead of Exposure Management at Check Point, told The Hacker News. "That's the trend to watch: capable, deniable, commercially-run crews doing state-level work at industrial scale, with universities as the perfect target. They offer enormous IP value, thin identity controls, and an open-access culture that phishing exploits directly. We've seen this blurring of cyber-criminal and state-sponsored activity before, but historically it's been more associated with Russian-speaking crews. What this case shows is that Iran and the IRGC are increasingly playing the same game." DLL sideloading campaignA new Grandoreiro malware campaign has been found abusing the legitimate Duplicate Files Finder (DFF) application to run malicious code via DLL sideloading. According to telemetry data from Acronis, Grandoreiro activity remains concentrated in Latin America, with Mexico, Spain, Peru, and Argentina accounting for the lion's share of infections. "The initial sample incorporates extensive anti-analysis functionality, including sandbox detection, virtual machine artifact checks, process blacklisting and environment profiling designed to evade automated analysis systems," Acronis said. "These checks are performed before any attempt to contact the command-and-control (C2) infrastructure, suggesting that avoiding analysis is a high priority for the operators." ClickFix meets BYOVDErrTraffic-generated ClickFix campaigns have been observed attempting to deliver Cruciferra, which, in turn, employs a legitimate but vulnerable driver ("DCRCVDrv.sys") as part of a BYOVD attack to escalate privileges and terminate security processes. ErrTraffic, sold by a threat actor named LenAI, is a malware-as-a-service (MaaS) framework and a traffic distribution system (TDS) that's designed to distribute multiple threats through compromised WordPress websites, ClickFix social engineering, and EtherHiding. In recent months, ErrTraffic has been used to deliver Remus Stealer, Vidar Stealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader, per WatchGuard. "Victims land on compromised WordPress sites injected with an obfuscated ErrTraffic-generated JavaScript loader," eSentire said. "The loader resolves its C2 domain by querying a Polygon smart contract, then sends a request to the C2 to retrieve the next stage to serve a ClickFix lure." The end goal of the attack is to launch Remus Stealer via process hollowing. Private AI processingOpenAI has announced a privacy-centric safety approach to monitoring model misuse. The company said it's previewing a new service to select customers that it calls Private Safety Processing, which keeps tabs on potential abuse without retaining customer data. "For ZDR deployments, customer content remains on infrastructure the customer controls," OpenAI said. "We are also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer. In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel." The system clearly takes aim at rival Anthropic, which has a 30-day retention policy for business customers who want to use its Mythos-class models. In a related development, Google has showcased Homomorphic Encryption Intermediate Representation (HEIR), which enables cryptographically secure private AI inference on encrypted inputs. "HEIR (Homomorphic Encryption Intermediate Representation) is an open-source compiler toolchain and development platform for homomorphic encryption," Google said. "In particular, HEIR can convert pre-trained AI models that operate on unencrypted data to operate on encrypted inputs." Guardrail-free AIA new AI-powered service called Kriminal AI offers paying customers a way to get answers about everything, without any of the filters or guardrails that are typically implemented by AI platforms. "Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch," the website claims. The service claims to have more than 2,300 users. Kriminal AI follows WormGPT, FraudGPT, and Xanthorox into a market that has expanded quickly to attract users who may be frustrated by safety, security, and ethical safeguards embedded into widely used models. Subscriptions for Kriminal AI start at $12.99/month and go all the way to $99.00/month. The most concerning aspect is that the service is not lurking in the dark web. It's accessible on the clearnet, and comes with a tagline: "No filters. No guardrails. No "I can't help with that." Kriminal.AI gives you raw, uncut intelligence — the questions other AIs refuse to touch." According to ThreatDown, the service appears to make use of Grok for primary inference; Google Cloud and Cloudflare for hosting; Anthropic's Claude for a long-context model layer; Llama routed through OpenRouter for certain specialized tasks; Tavily for live search; NowPayments for cryptocurrency checkout (no KYC included, apparently); and Cloudflare/Let's Encrypt for DNS and TLS. ATT consent changesApple has agreed to make changes to its App Tracking Transparency (ATT) feature in Germany, after the Federal Cartel Office, or FCO, found the feature gave its own apps more favorable consent prompts than those of third-party developers. Apple has four months to implement the changes after. According to a statement issued by Apple, the changes will apply in almost all European Union countries. "The differences between the consent request used for Apple’s own offerings and the consent request predefined by Apple for third-party apps exceeded what could be justified based on differences in types of data processing," FCO said. "The wording, design and selection options of the request used for Apple’s own offerings had the potential to encourage users to give their consent, whereas they had the potential to discourage consent for third-party apps. In addition, third-party apps in some cases had to request consent several times even when users had already given data protection law-compliant consent." Apple was fined €98.6 million (then $116 million) in December 2025 by Italy's antitrust authority after finding that ATT restricted App Store competition. Refrigeration controllers exposedClaroty's Team82 has discovered 23 vulnerabilities in Copeland XWEB Pro controllers, including those that can be chained to bypass security mechanisms and achieve root-level remote code execution. A compromised controller could be used to remotely manipulate refrigeration equipment, including cooling fans and compressors, and conceal the resulting temperature increase while silently allowing the food to spoil. Multiple vulnerabilities have also been disclosed in Danfoss AK-SM 800A refrigeration controllers, including a "hidden 'code-of-the-day' authentication mechanism that could be abused to bypass normal authentication, a command-injection vulnerability leading to remote code execution." A second flaw allowed authenticated users to inject arbitrary Nginx configuration directives, which could be abused to manipulate web traffic and trigger a denial-of-service condition. All the identified vulnerabilities have been fixed by the respective vendors. C2 hidden in whitespaceA hand-written Windows backdoor has been found to store its C2 domain as the number of trailing spaces in a fake desktop.ini file. The 12 KB backdoor was discovered by Gen Digital on a single corporate workstation while hunting for unusual WMI persistence. "The malware was small, had a limited command set and disguised itself as legitimate Realtek software," Gen said. "Its most unusual feature was its configuration: the address of its command-and-control server was not stored as readable text or encrypted data, but encoded in the number of spaces on each line of a Windows 'desktop.ini' file. To a user, and to many automated inspection systems, the file would appear almost empty. To the malware, those spaces spelled out its server address." There is no evidence connecting the backdoor to a known threat actor. The absence of related samples indicates that it may have been a deliberately targeted operation. Maximum-severity RCEA maximum-severity security flaw in Gogs (CVE-2026-52813, CVSS score: 10.0) could be exploited to achieve remote code execution through Git hooks. "Organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals," according to a June 2026 advisory. "This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating a nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE)." The issue was addressed in version 0.14.3, alongside patches for CVE-2026-52810 (a logic bug to write on read-only repositories) and GHSA-6vxv-wg6j-5qwp (an XSS flaw in the outdated version of "jsvine/notebookjs" used to render Jupyter notebook files). Aikido Security has been credited with discovering and reporting the flaws. Memory leak via PostScriptDetails have emerged about a now-patched out-of-bounds read flaw in Apple macOS Spotlight (CVE-2026-43774, CVSS score: 5.5) that could be exploited by a malicious app to access sensitive user data. The vulnerability was patched by the iPhone maker in late July 2026. "The vulnerability is in the Spotlight PostScript plugin," Iru researcher Csaba Fitzl said, adding an attacker can use a specially crafted .ps file to trigger the vulnerability. It requires three conditions to be met: (1) The file is at least 4000 bytes, (2) A DSC comment keyword (e.g., %%Creator:) appears somewhere in the first 4000 bytes, and (3) The bytes following the keyword, up to byte 4000, contain no control characters. Unauthenticated CI/CD takeoverA critical security flaw has been disclosed in @circleci/mcp-server-circleci that could result in remote code execution by means of a specially crafted request. "With one well-placed request, an attacker achieves an unauthenticated RCE in your CI/CD pipeline, taking full control of your build secrets and cloud identities," Remedio said. The attack takes advantage of the fact that the Host and Origin headers associated with an HTTP request used to block browser-based attacks can be set by a network-adjacent threat actor. "Send a simple HTTP request that says Host: localhost in the HTTP header with no Origin, and you get right through," Remedio said. "Once in, you can freely communicate with connected tools. Call the "run pipeline" tool, hand it the pipeline configuration you wrote, and add a step to run your commands. CircleCI executes it using the organization's token." The vulnerability has been fixed in version 0.19.2 of the npm package. Workflow-to-RCE chainA critical vulnerability in n8n, an open-source workflow automation platform, can allow an authenticated user with permission to create or modify workflows to exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes and achieve remote code execution on the n8n instance. The issue (CVE-2026-33696, CVSS score: 9.4) has been fixed in versions 2.14.1, 2.13.3, and 1.123.27. Security researcher Simon Koeck, who discovered the Flaw, said the prototype pollution alone is serious enough to crash the entire n8n instance, but can be chained to obtain full code execution and allows the attacker's command to be run as the n8n process user. Cable cut stopped intrusionIn late 2024, reports emerged of a Salt Typhoon campaign that targeted T-Mobile and other major U.S. telecommunications companies as part of a cyber espionage effort to gain access to valuable customer data. Although the activity was caught before the Chinese cyber spies could siphon any data from T-Mobile's networks, the company has now revealed to Bloomberg that its staff spent months looking for suspected intruders without much success, only to eventually trace unusual behavior on one of its systems coming from a Chicago router belonging to a different telecom company. Jeff Simon, T-Mobile's chief information officer, said he and three others drove to the data center that housed the compromised device and "pulled out a pair of scissors" to cut the cable. AI exploitation gainsChinese AI startup Z.ai has released GLM-5.3, a new AI model that it said is better suited for complex coding and long-horizon tasks. "GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain, where it more than doubles GLM-5.2 on exploitation benchmarks," it said. "GLM-5.3 did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains," Z.ai said it has been working with several security teams in China to run its open-source models against real-world codebases, identifying 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. "The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols," it said. "Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years." Despite these advances, benchmarks show that GLM-5.3 lags behind Anthropic Mythos 5 in converting discovered flaws into working attacks. The useful part of weeks like this is that the attacks rarely begin with magic. They begin with trust, exposure, weak assumptions, and things nobody thought worth abusing. That leaves plenty to fix. Tighten what gets trusted, question the defaults, and keep looking at the boring edges. Attackers clearly are.
thehackernews.comAug 20, 2026extracted
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a lot of small openings turning into bigger problems. Here’s what stood out. ⚡ Threat of the Week Suspected China APT Behind Exploitation of New VMware Flaw — A suspected China-nexus APT is assessed to be behind the exploitation of a newly patched security flaw in VMware vCenter. The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. In at least one compromised instance, the attacks led to the deployment of a backdoor and. a reverse SSH binary, with the attack ultimately leading to the deployment of Babuk-derived ransomware. "Based on the case we investigated, however, we do not believe ransomware was necessarily the primary objective," QUIRSO said. "To us, its deployment looks more like a smoke screen intended to distract from the underlying intrusion and, importantly, hinder subsequent forensic analysis by encrypting evidence. We therefore see the ransomware activity in this case as potentially serving the broader intrusion rather than being its ultimate objective." AI Adoption Is Outpacing Governance, New SANS Survey Finds Seventy-eight percent of practitioners now say AI is part of their cybersecurity strategy, up from 50% last year. Governance hasn't kept pace: just 36% have a formal AI risk program. See where 536 security professionals say programs are falling short, and what to do about it. Read the Findings ➝ 🔔 Top News Apple macOS Flaw Exploited to Drop Crypto Miner — A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials. The shortcoming was addressed as part of an emergency update in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 earlier this month. The Netherlands National Cyber Security Center (NCSC-NL) said it received a report indicating active abuse of the vulnerability across multiple systems on which port 5900 was accessible from the internet. "In all these cases, root had gained access to the affected system and placed a Monero crypto miner," the agency said. Lazarus Exploits New Windows 0-Day — The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity is part of Operation Dream Job, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers to steal sensitive data and install malware. The attacks have been found to exploit CVE-2026-68820 (CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026. The attacks have been observed to deliver ForestTiger and a new backdoor called Troy. GeoServer Patches Critical Flaw Under Attack — GeoServer has released patches for a critical SQL injection vulnerability that can lead to remote code execution (RCE). The issue, which has yet to be assigned a CVE identifier, has been patched in versions 3.0.1, 2.28.5, and 2.27.6. Per watchTowr, the vulnerability witnessed active exploitation within hours of public disclosure and that it has seen hundreds of attempts originating from a small pool of IP addresses. GeoServer project maintainers told The Hacker News that the flaw was responsibly disclosed and was scheduled to be addressed in their regular release cycle, when details of the flaw became public knowledge last week. Amnesia Stealer Goes Beyond Data Theft — A newly discovered macOS stealer family called Amnesia Stealer has been found to target macOS users via ClickFix attacks. The malware, besides stealing data from 16 Chromium-based web browsers as well as other sensitive information, such as passwords, cryptocurrency wallets, Apple Notes, documents, and iCloud Keychain data, includes a streaming module that allows the attacker to interactively control the victim's web browser. One notable aspect of the stealer is its ability to copy the victim's Chromium profile, including its authentication state, and load it into a headless browser on the infected system to access the authenticated sessions. The streaming module can duplicate user profiles in Chromium-based browsers, including Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, and Brave, and establish a WebSocket channel that connects to the operator's relay and receives commands, such as navigation and mouse clicks. The remote-control component is built using the Chrome DevTools Protocol (CDP). A second WebSocket channel connects to the local headless Chromium instance. "The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation and tab management," Jamf said. "In effect, the remote_stream command turns an infected host into a live, operator-driven browser running the victim's authenticated sessions, which is a materially different level of access from file collection." Amnesia Stealer is the first documented macOS malware to combine a cloned Chromium profile with CDP-based, real-time remote control to allow interactive access. From GhostCommit to GhostSplice — A new attack technique called GhostSplice can sidestep guardrails built around AI coding assistants and parse malicious requests that are split and hidden in a different channel, such as an MCP tool description, a tool result, and a sampling message. Each of these requests is perfectly benign on its own and processed by the assistant without refusing them. "The entire attack rests on the following fact: All three of the tool channels discussed above, together with your files and your own chat, pour into one block of the assistant's memory," ASSET Group said. "There does not exist any marking that separates the content based on its respective source. Therefore, the assistant reads it all as a single page." The attack has been described as a case of cross-channel trust fragmentation. "Due to the absence of a wall between content received from different sources (e.g., different tool channels), the attacker never needs any single one of this content to look dangerous. Instead, the idea is to embed a harmless piece in each source, and the assistant stitches them back into one instruction." Using Chrome DevTools Protocol for Data Theft — New research from SpecterOps detailed a post-exploitation technique that allows Chromium's CDP protocol to be enabled inside a live Google Chrome or Microsoft Edge process on Windows with an end goal to steal cookies, saved data, and authenticated browser sessions provided an attacker already has code execution permissions on the compromised host. "Cookie protections like ABE and device-bound session cookies make it harder to steal and replay session material, but they do not remove the value of an authenticated browser to adversaries," SpecterOps said. "Once CDP is enabled inside a Chromium browser, an operator can use the browser context to sidestep those replay protections, access authenticated applications, and collect saved data. Enabling CDP is a reminder that the next evolution of cookie theft may not require stealing the cookie DB and ABE key at all." ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-68820 (Microsoft Windows), CVE-2026-58231 (SAP Commerce Cloud), CVE-2026-48362, CVE-2026-71398, CVE-2026-27302 (Adobe), CVE-2026-20349 (Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense), CVE-2026-53413, CVE-2026-53414, CVE-2026-53415 (Zoom), CVE-2026-65400 (Apple macOS), CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348 (ClamAV), CVE-2026-18412 (OpenCart), CVE-2026-66147, CVE-2026-66145 (SonicWall), CVE-2026-6726, CVE-2026-6727 (Trusted Platform Module 2.0 reference implementation), CVE-2026-26035, CVE-2026-70468, CVE-2026-70465 (Fortinet), CVE-2026-65640 (WordPress), CVE-2026-65321 (PyAthena), CVE-2026-43637 (Cornac), CVE-2026-63720 (datamodel-code-generator), an SQL injection vulnerability in GeoServer, and multiple vulnerabilities in WireShark.. 🎥 Cybersecurity Webinars How to Control the Open-Source Security Debt Created by AI Coding Tools → Learn how AI coding tools are expanding unvetted open-source use, accelerating vulnerability backlogs, and weakening existing governance. This webinar shows how to measure the resulting remediation debt, connect it to breach, audit, and productivity risks, and identify which governance models can contain it without slowing development. AI Can Build Exploits in Minutes. Can Your Security Team Keep Up? → AI is collapsing the time between vulnerability disclosure and attack. Advanced models can now uncover flaws, generate working exploits, and chain them into complete attack paths at machine speed. This webinar presents a practical framework for gaining the visibility, context, and response speed needed to investigate and stop threats before attackers pull ahead. 📰 Around the Cyber World Security Flaw in FileRun — VulnCheck disclosed details of CVE-2026-14863 (CVSS score: 8.7), a high-severity operating system command injection flaw in FileRun that could lead to remote code execution. "FileRun's thumbnail extractors build shell commands by pasting the uploaded file path into a double-quoted string and handing it to exec(), and the filename sanitizer lets $() through, so a file named $(payload).mp4 runs its payload the moment a thumbnail is generated," security researcher Valentin Lobstein said. "Any authenticated user with upload permission gets code execution; when a public file request weblink exists, so does anyone who knows its token, no account required." The issue, which affects versions up to and including 2026.2.0, has been fixed in 2026.2.1. ClickFix Leads to ACR stealer and GhostPipe — ThreatLocker disclosed an attempted ClickFix attack that employs embedded scripts, steganographic payload extraction, and obfuscation to deploy an advanced iteration of ACR stealer and a secondary payload dubbed GhostPipe. The ClickFix attack originated from a fake CAPTCHA prompt being served on a compromised domain, resulting in the execution of a PowerShell command that downloads an MP3 file, which is then executed using MSHTA to launch a VBScript that's responsible for running intermediate payloads designed to gather system information and extract from a remotely hosted JPG file a PowerShell script. The script serves as an in-memory module shellcode launcher to deploy ACR Stealer. The malware also contacts a C2 server to fetch secondary payloads, including a PowerShell script called GhostPipe. "This seemingly unknown script performs a proxy-based AiTM attack with the sole purpose of stealing Google logins," ThreatLocker said. "The methods used are comprehensive and inherently support relaying MFA to successfully capture credentials." Flaw in Citrix NetScaler — Citrix appears to have silently addressed a heap overflow vulnerability in NetScaler that can be exploited to achieve remote code execution. The issue was patched as part of updates released towards the end of June 2026. watchTowr said the vulnerability likely corresponds to CVE-2026-8452, which has been described as a memory overflow vulnerability that could lead to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server. The vulnerability, per the threat intelligence company, can be turned into code execution to drop a PHP web shell that can survive the NetScaler packet engine being respawned, and ultimately execute commands with root privileges. Shortly after details of the flaw became public, Defused Cyber said it observed active in-the-wild exploitation efforts two calendar days later. Ethereum Malware Loader Goes After Portuguese-Speaking Users — Portuguese-speaking users are the target of a malware loader that uses the EtherHiding technique to dynamically locate attacker infrastructure and distribute additional payloads. "The multi-stage infection chain combines obfuscated JavaScript, Node.js, DLL side-loading, and a malicious Chromium browser extension capable of targeting Chrome and Microsoft Edge to collect cookies and web storage, capture screenshots, monitor browser activity, and receive remote commands," WatchGuard Threat Lab said. The Israel National Digital Agency (INDA), in its own analysis of EtherHiding, said the technique has been used as a delivery backend, a C2 channel, a victim database, and skimming infrastructure. In another interesting twist, attackers have been found to shift to the BNB Smart Chain testnet, essentially eliminating gas fees and making the whole operation free. "Because writes there are free, unlimited, and leave no financial trail, recent reporting has found malware command-and-control backends running entirely on a testnet," INDA said. Thousands of Exposed Fuel Gauges Dropped from the Internet — BitSight said it observed a dramatic drop in internet-exposed Automatic Tank Gauge (ATG) systems in the U.S., with the number declining by more than half. "From March to June, there was over a 55% drop in exposed IP addresses," it said. "Globally, exposure fell 49% from that same March peak, with the U.S. accounting for most of the decline. For ten months, from June 2025 through March 2026, the U.S. held a band of roughly 4,300 to 5,300 unique exposed IPs, averaging 4,815 across 2025. Then April fell 27.6% in a single month, May fell another 31.8%, and June continued down. By June, the exposed population was 56% below the March peak." Phantom Enigma Campaign Targets Brazil — An active PhantomEnigma campaign has been observed abusing compromised government infrastructure and fake police-themed documents to target banking and public-sector organizations in Brazil. The phishing messages are presented as official notices and bypass email security filters to deliver a modular Node.js backdoor that collects system data, sets up persistence, and connects to rotating C2 infrastructure. It can also execute JavaScript or deliver stealers, loaders, RMM software, and other malware. Some aspects of the activity overlap with prior reports from Positive Technologies. F.B.I. Agent Charged With Unauthorized Crypto Withdrawals — An F.B.I. counterintelligence agent has been charged with illicitly obtaining about $1 million worth of cryptocurrency, largely through unauthorized withdrawals from a criminal target overseas. According to The New York Times, the agent claimed he had begun taking the money in late 2024 or early 2025, and made 10 or 12 withdrawals altogether by making use of a seed phrase to the suspect's account that the F.B.I. had obtained during its investigation of the individual. Ukraine Dismantles Fraudulent Call Centers — Ukrainian authorities disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Per the Ukrainian police, the call centers were associated with schemes relating to callers impersonating bank employees, fraudulent investment services, cryptocurrency platforms, and attempts to gain remote access to victims' devices or trick them into handing over sensitive data under the guise of suspicious transactions. Some cybercriminals collected personal information about prospective victims and shared or sold those records to other operations. "Call centers were staffed by administrators, operators, and other participants in the schemes, and ready-made conversation scripts, databases of potential victims, special software, and tools for hiding and further withdrawing funds were used," the police said. During the probe, 3,336 pieces of computer equipment, 1,346 phones, over 5,200 SIM cards, 90 bank cards, access to 20 crypto wallets, and 22 cars were seized. About $2 million, €64,000, cash in hryvnias, a kilogram of bank gold in bars, and jewelry were also confiscated. North Carolina Man Sentenced for Cyber Extortion Scheme — Cameron Curry, 27, of Charlotte, North Carolina, was sentenced to 24 months in prison for carrying out an "extensive cyber extortion scheme" against an unnamed D.C.-based international technology company. In March 2026, Curry was convicted of six counts of transmitting or willfully causing interstate communications with the intent to extort a victim company. "Curry misused his position to access the victim company's personnel and other sensitive corporate records, which he then used to carry out the cyber extortion scheme," the U.S. Justice Department said. "Curry hatched his extortion scheme after he learned that his contract was not going to be renewed and that he would no longer be employed by the company." ExfilSquad's Access to Data from 13 Organizations — A new analysis of data samples published by the ExfilSquad data extortion group has confirmed "they have access to sensitive data." Fortra said the breaches were most likely limited to unauthorized access of D365 instances. "The leading theory on the initial attack vector that enabled exfiltration is misconfigured Microsoft Power Page portals that allowed for public read access," it said. "The observed leaked data formats are consistent with Microsoft Dataverse exports, suggesting unauthorized read access may have been achieved, and victims found by crawling for misconfigured Microsoft Power Portals or other enumeration techniques." OpenAI Rolls Out Computer History in ChatGPT — OpenAI replaced Chronicle, which builds memories from screen captures to make ChatGPT and Codex more aware of context, with Computer History. "Computer History turns your activity across apps and websites into memories and a timeline that ChatGPT and Codex can reference," OpenAI said. "You can ask natural questions about recent work, pick up where you left off, understand patterns in how you work, and turn repeated workflows into skills or automations." Computer History is off by default for ChatGPT Pro, Business, and Enterprise users in the ChatGPT desktop app on macOS. The feature is reminiscent of Microsoft's controversial Recall, which attracted scrutiny for relying on periodic screenshots to capture and index relevant information. Unlike Chronicle, which also used screenshots, Computer History relies on capturing interactions (e.g., clicks, typing, keyboard shortcuts, app switches, and context) to allow the AI to understand user workflows. "Computer History records interaction events and does not capture your screen or audio," OpenAI said. "You control which apps and websites contribute, can see and pause collection from the macOS menu bar, and can inspect or delete your history at any time." That said, it's worth emphasizing that Computer History files can contain sensitive information. "They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them," OpenAI cautions. "Protect your Mac account and exclude sources you do not want included." OpenAI also warned that Computer History increases the risk of prompt injection from content in apps and websites, as the AI system can follow instructions when visiting a website containing malicious instructions. Temporary interaction event files are retained for up to 48 hours before they are deleted. However, they can be used to create memory files that can remain for extended periods of time until users explicitly delete or clear them. China-linked LightSpy Activity Detected in Over 13 Countries — The modular implant known as LightSpy has evolved into a broader surveillance tool that's in use in more than 13 countries and regions, including Singapore, Hong Kong, the Netherlands, Pakistan, Japan, China, Malaysia, Germany, the U.S., Thailand, Indonesia, South Korea, Austria and Turkey, Arctic Wolf Labs said. This includes previously unreported router-focused capabilities along with live router implants in Europe and Africa. "The findings expand the potential impact of the surveillance framework beyond individual devices: router access can provide visibility into every device connected to a home or office network and may persist after phones are replaced, devices are factory-reset, or operating systems are upgraded," a spokesperson for the company said. LightSpy infrastructure spans several countries, including 117 servers and 35 domains impersonating Asian electronics manufacturers and router-management services. Evidence indicates that LightSpy functions as a commercialized surveillance platform, with customer branding, billing functionality, and a demonstration environment used to market the framework to prospective buyers. The platform is assessed to be the work of a Chinese contractor after one of the operators used the LightSpy administrator's panel to place an order with KFC using their real name and office address. Trivy Supply Chain Attack Exposed 2,500+ Companies — A new analysis from SOCRadar has revealed that 95% of organizations impacted by the LiteLLM supply chain attack earlier this year were exposed before, coinciding with the compromise of the Trivy scanner. "Organizations did not need to install LiteLLM directly to be exposed," the cybersecurity company said. "The package could arrive through frameworks such as DSPy, MLflow, CrewAI, OpenHands, and Arize Phoenix, while its payload executed at Python startup without requiring a LiteLLM import." The incident was attributed to a threat actor known as TeamPCP. Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records — An active Microsoft Azure exfiltration campaign is being driven by a threat actor named "TheHatman," who has "flooded" cybercrime forums with enterprise employee databases. The data is said to have been downloaded directly from the organizations’ Azure/Entra portals using compromised credentials, although the exact intrusion vector remains unknown. The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics. Some of them include McDonald's, TCS, Vodafone, HCL Technologies, Kyndryl, Gap, Hexaware, and Wyndham Hotels. "Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure," Hudson Rock said. Conclusion That’s the week. Some attacks needed a real exploit. Others just needed an exposed system, a stolen login, or one weak link buried in the stack. The useful part is knowing which kind you’re dealing with before it becomes your problem. Patch what matters, close what should not be public, and keep an eye on the boring stuff. It keeps winning.
thehackernews.comAug 17, 2026extracted
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems trusted the wrong instructions. Same soft spot throughout: trust placed one layer too early. Below is the full recap, since this is apparently what counted as a normal week. ⚡ Threat of the Week NetNut Residential Proxy Network Disrupted — Google, in collaboration with the U.S. Federal Bureau of Investigation (FBI), Lumen, and other partners, took action against the NetNut residential proxy network, also known as Popa, building upon its takedown of IPIDEA in January 2026. Google said it disabled Google accounts and associated Google services used by NetNut for malware command-and-control (C2) and updated Google Play Protect, in addition to disabling applications known to incorporate NetNut SDKs. The size of the network is estimated to be at least 2 million devices globally. "NetNut populates its botnet by distributing SDKs for devices commonly found in homes, such as smart TVs and streaming boxes," Google said, adding it "identified NetNut botnet plugin components for large-scale botnets such as BADBOX 2.0." The end goal is to leverage the route traffic through these devices, allowing bad actors to mask malicious activity. The devices are pre-installed with malware before purchase or because users unknowingly download applications containing hidden proxy code. Case Study: How 1Password Secured Canva's Path to 260M Users When Canva 5xed their headcount across 8 countries, they needed security that could scale as fast as their business. See how 1Password helped them onboard teams in minutes, eliminate secret sprawl, and keep engineering moving. Learn More ➝ 🔔 Top News WhatsApp Gets Usernames But Impersonation Concerns Are Raised — WhatsApp officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through usernames, as opposed to directly sharing their phone numbers. The feature is expected to be generally available later this year. The rollout marks a shift in how people identify one another on the messaging app. It has also drawn scrutiny in India, its largest market, over concerns it could be abused to impersonate public authorities, financial institutions, government departments, and other prominent figures. While Meta told TechCrunch it reserves usernames for public figures, government entities, and some of their variations so that only legitimate users can claim them, it's currently not clear how it decides which lookalike usernames get reserved and which don't. ChocoPoC RAT Targets Vulnerability Researchers with Fake PoC Exploit Repos — Security researchers on the lookout for Python-based proof-of-concept (PoC) repositories on GitHub claiming to exploit new CVEs are being tricked into executing malicious code that delivers ChocoPoC. While the PoC in itself looks clean, the actual malware sits inside a dependency named "skytext" pulled by the PoC. The malware is a full-featured trojan capable of harvesting passwords, cookies, autofill, and history from Chrome, Brave, Edge, and Firefox. It also captures text files, notes, local databases, shell history, network settings, and a list of running processes, as well as supports running arbitrary shell commands or Python code. 19-Year-Old Alleged Scattered Spider Suspect Extradited to the U.S. — Peter Stokes (aka Bouquet, Spencer, and Jordan), a 19-year-old man with dual U.S. and Estonian citizenship, was extradited from Finland to the U.S. to face criminal charges over his involvement in a criminal scheme in connection with the Scattered Spider hacking group. Finnish police arrested him in April 2026. Stokes and other Scattered Spider members are alleged to have breached an unspecified "luxury-jewelry retailer" in May 2025 and demanded an $8 million ransom in cryptocurrency. The company incurred at least $2 million in losses from business disruption, incident response, and recovery efforts. Stokes was involved in at least four Scattered Spider breaches, the Justice Department said. Stokes faces charges of fraud, conspiracy, and computer intrusion. Ousaban Banking Trojan Targets Spain and Portugal — A new Brazilian banking trojan called Ousaban has been observed using fake PDF documents containing a link to a malicious web page that scans the user's environment. "If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack," Fortinet said. "The final payload is an EXE file that is dropped onto the victim's computer and executed by the VBS script." Ousaban gets triggered when victims visit a banking site, at which point it captures screenshots and keystrokes, tampers with the clipboard, and enables remote control. AI-Generated Browser Ransomware Exploits Chromium File Access API — A new malware artifact generated using DeepSeek has constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the browser on Windows, Linux, macOS, and Android devices. The approach is limited to web browsers that expose the picker-based File System Access API. This includes Google Chrome and other Chromium-based browsers across Windows, macOS, ChromeOS, Linux, and Android. There is no evidence that the browser-native ransomware pattern has been abused in the wild. "What we are witnessing is a fundamental shift in how novel cyber attacks are born," Check Point said. "For the first time, we have evidence that an AI model can independently reason across legitimate platform features and surface a working attack technique that humans had only theorised about – without the attacker ever knowing the underlying API existed." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-48276, CVE-2026-48283, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48313, CVE-2026-48315 (Adobe ColdFusion), CVE-2026-48286 (Adobe Campaign Classic), CVE-2026-50548, CVE-2026-50549 (Cursor), CVE-2026-46242 aka Bad Epoll (Linux Kernel), CVE-2026-6682, CVE-2026-6687, CVE-2026-6688 (FatFs), CVE-2026-8037 (Progress Kemp LoadMaster), CVE-2026-28701, CVE-2026-33560, CVE-2026-31928 (Daktronics Controller Firmware), CVE-2026-41120 (Dell Wyse Management Suite), CVE-2026-41492 (Dgraph), CVE-2026-55047 (Anthropic Buffa), from CVE-2026-13774 through CVE-2026-13788 (Google Chrome), CVE-2026-48519, CVE-2026-48520, CVE-2026-7528, CVE-2026-7524 (Langflow), CVE-2026-3199 (Sonatype Nexus Repository), CVE-2026-12166, CVE-2026-12167, CVE-2026-12168 (Little Orbits GameFirst Anti-Cheat driver), CVE-2026-56141, CVE-2026-56142, CVE-2026-50242, CVE-2026-50242 (JetBrains), CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 (ClamAV), CVE-2026-20191 (Cisco Catalyst Center), CVE-2026-53917, CVE-2026-54475, CVE-2026-49877 (Apache ActiveMQ), CVE‑2026‑13050, CVE‑2026‑13053, CVE‑2026‑13054, CVE-2026-13079 (WatchGuard Fireware OS), CVE-2026-45504 (Microsoft Exchange Server), CVE-2026-14191 (WinRAR), CVE-2026-44024, CVE-2026-44025 (Fluentd), CVE-2026-55957, CVE-2026-55956 (Apache Tomcat), CVE-2026-13136, CVE-2025-15660 (Synology MailPlus Server), CVE-2026-22678, CVE-2026-49102, CVE-2026-49103, CVE-2026-42210, CVE-2026-56022 (Webmin), from CVE-2026-12044 through CVE-2026-12050 (pgAdmin), CVE-2025-66273, CVE-2025-66279, CVE-2026-22893 (QNAP QTS, QuTS hero, QuTS cloud, and QVP), CVE-2026-11310, CVE-2026-11999, CVE-2026-6679, CVE-2026-55958, CVE-2026-55960, CVE-2026-55961 (wolfSSL), CVE-2026-48611 (phpBB), and CVE-2026-20896 (Gitea). 🎥 Cybersecurity Webinars AI Attacks Are Moving Faster Than Your Defenses → AI is helping attackers write better lures, change tactics faster, and run campaigns at a scale many security teams are not built to handle. This webinar breaks down how AI-powered threats like Mythos gain access, move through environments, and expose the limits of traditional network-based defenses—then shows how teams can reduce attack surface, stop lateral movement, and contain risky behavior before it turns into a major incident. Your AI Agents Need a Kill Switch → AI agents can do more than make mistakes—they can expose credentials, bypass controls, and become a new attack surface inside the business. This webinar uses hands-on findings from OpenClaw testing to show where agentic AI breaks down, why guardrails are not enough, and how teams can reduce risk with identity-based governance, least-privilege access, short-lived secrets, logging, auditing, and visibility into shadow AI use. 📰 Around the Cyber World Indirect Prompt Injection Attacks Targets AI Agents for Typosquatting and Payment Scam — Threat actors are using indirect prompt injection (IPI) to hide instructions in websites, attempting to trick an AI agent into following the attacker’s instructions. "The observed campaigns combine SEO poisoning with CSS/HTML abuse to both manipulate search results and conceal prompt-style instructions that influence AI decision making," Zscaler said. "When AI agents misclassify malicious websites as legitimate, they increase the risk of context contamination and downstream Retrieval-Augmented Generation (RAG) poisoning." Dropping Elephant Delivers In-Memory RAT — The threat actor known as Dropping Elephant (aka Patchwork) has been observed using a China-themed energy-sector contract lure to deliver a heavily reworked, in-memory remote access trojan (RAT). "This campaign demonstrates advanced evasion techniques, including DLL side-loading with a legitimate Microsoft binary (Fondue.exe) and the use of 'Donut' shellcode to map the RAT directly into memory, effectively bypassing traditional disk-based security controls," Rapid7 said. "The revamped RAT significantly complicates detection by using control-flow flattening, runtime API reconstruction, and hardened C2 communications." The malware supports directory listing, file upload/download, screenshot capture, and command execution capabilities. Microsoft Updates SSPR to Require Registered Authentication Methods — Starting September 7, 2026, Microsoft said Entra self-service password reset will require users to have explicitly registered authentication methods for password reset verification, while explicitly disallowing directory-sourced contact information unless registered. "Currently, SSPR may allow users to verify their identity using contact information stored in directory attributes such as mobile phone, business phone, and alternate email, even if those values were never explicitly registered as authentication methods," Microsoft said. "To strengthen identity security, SSPR will require explicitly registered authentication methods for verification. This change is part of Microsoft’s Secure Future Initiative and ensures password reset verification is based on trusted, user-validated methods rather than directory-sourced attributes." The development comes as the Windows maker has introduced jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms, preventing Entra credentials from functioning on jailbroken/rooted devices. Scammers Exploit Trusted Brand Names to Drive Casino Traffic — Scam advertising campaigns are impersonating trusted brands to drive consumers to unrelated online gambling sites. "These campaigns utilize paid social ads, fake app store pages, and Progressive Web Apps to make users believe that well-known brands have launched 'official' casino or slot products," Netcraft said. "The scams begin with an ad on social media platforms such as Facebook, Instagram, and TikTok. The ad claims that a recognizable brand has launched '[Brand] Slots' or a similar gambling product. Upon interacting with the ad, the user is taken to a fake landing page designed to look like an official app store listing or branded game page. Instead of installing a real app, the user is prompted to add a Progressive Web App to their device, which opens an unrelated online casino through affiliate tracking links." PhishLumos as a Way to Counter Cloaking-Based Phishing Threats — As phishing continues to be a persistent threat in cybersecurity, researchers from Tokyo Metropolitan University and NTT Security Holdings have demonstrated PhishLumos to counter campaigns that evade automated scanners through cloaking and selective blocking techniques. "When content is missing, deceptive, or inaccessible, PhishLumos pivots to infrastructure evidence, including shared domains, IP addresses, certificates, and historical scan metadata," the researchers said. "It consolidates observations into a typed property graph knowledge base with a deterministic, idempotent merge operator and provenance for auditable investigations. A supervisor agent coordinates specialized agents and synthesis agents powered by large language models to profile campaigns and generate empirically validated detection rules for deployment in existing controls." CVE Explosion in the AI Era — With artificial intelligence (AI) and large language models (LLMs) accelerating vulnerability discovery, a new report from ProjectDiscovery has found that 30,550 CVEs have been published so far in 2026, a figure that's expected to eclipse 2025's 49,458 CVEs. Of these, 2,906 are rated critical, and 11,187 are rated high in severity. In contrast, a total of 30,361 CVEs were published in 2023. "The exploitable surface is doubling faster than defenders can absorb," ProjectDiscovery said. When the median time-to-exploit is days and the mean is negative, a 55-day critical-remediation cycle is not a process, it's an open door. If attackers are weaponizing bugs in minutes with AI, the response, finding them, proving they're real and handing developers a fix, has to run continuously and autonomously, not on a calendar." New ClickFix Campaign Uses Blockchain C2 — An active malware-as-a-service (MaaS) operation is abusing the Polygon (MATIC) blockchain as a resilient C2 configuration with a ClickFix lure. More than 130 compromised lure websites have been detected so far as part of the campaign. "Compromised websites are injected with a script named tracker.js, appearing as 'JokerStat Analytics Tracker,'" Palo Alto Networks Unit 42 said. "In addition to the clipboard injection, this script performs screenshot and victim-session telemetry exfiltration every 2 minutes." When a victim visits a compromised site, the injected JavaScript performs a blockchain lookup to fetch the C2 server URL. "After C2 resolution, tracker.js starts collecting victim telemetry, including pageview events, heartbeat and screenshots," Unit 42 said. "The same tracker.js then injects the clipboard content personalized per victim. The victim sees a fake CAPTCHA overlay and follows the instructions leading to a ClickFix attack." The attack culminates with the deployment of an infostealer written in Ruby. 2 Venezuela Nationals Sentenced in ATM Jackpotting Attacks — Two illegal aliens from Venezuela, Carlos Javier Padron, 36, and Arnoldo Cabrera Torrealba, 37, were sentenced to 78 months in prison in the U.S. for their involvement in ATM jackpotting activities. The two individuals pleaded guilty to one count of conspiracy to commit bank burglary and one count of computer fraud and intentional damage to a protected computer. The defendants built and deployed a variant of the Ploutus malware on ATMs across the country and used it to withdraw money without authorization. "The conspiracy relied on individuals, including Padron and Torrealba, to deploy the Ploutus malware onto ATMs in person," the U.S. Justice Department said. "Once installed and activated, the malware permitted the co-conspirators to issue commands to the cash dispensing module of the ATM in order to force unauthorized withdrawals of currency." Padron and Torrealba were also ordered to jointly pay $1.53 million in restitution. More than 90 other defendants have been charged over their roles in the operation. Bypassing Microsoft Entra Conditional Access Policies — NetSPI said it found a way to bypass Microsoft Entra Conditional Access Policies by abusing Nested App Authentication to return access tokens for the Microsoft Graph API. "It was possible to use certain Nested App Authentication (or BroCI) flows to bypass any Conditional Access policy," security researcher Thomas Byrne said. "This vulnerability served mainly as a persistence mechanism as it would have required a successful phishing attack to return an initial refresh token before the vulnerable authentication flows could be carried out." A fix for the issue has since been rolled out by Microsoft. Threat Actors Target Laravel Livewire Flaw — More than 6,100 applications have been compromised as part of a campaign targeting CVE-2025-54068, a critical unauthenticated RCE vulnerability in Laravel Livewire, to deliver a credential stealer by means of a shell script. The stealer harvests database-related configurations, Stripe secret keys, SMTP passwords, Google OAuth client secrets, JWT secrets, and AWS IAM credentials from .env files and exfiltrates them to a remote server. The campaign is assessed to have been underway for several months. "Recovery and analysis of the attacker's exfiltration infrastructure revealed credentials harvested from 6,167 distinct applications spanning dozens of countries and sectors, from e-commerce and healthcare to financial services, education, and government," Imperva said. "The attacker’s FTP server contained 1,851+ database dumps and 18+ email lists with over 26 million addresses, indicating the stolen credentials were being actively exploited." The activity has been attributed to an Indonesian-origin threat actor. Booking.com Partner Firms Targeted in TONResolver Campaign — Attackers are targeting employees of Booking.com partner companies in Japan using phishing emails that impersonate guest complaints and review requests to trick hotel staff into executing malicious files. The emails are sent using the notification functionality of a scheduling tool service, allowing them to bypass SPF, DKIM, and DMARC checks. The attacks led to the deployment of TONResolver, which abuses the Open Network (TON) blockchain platform as a dead drop resolver. "In this attack, a ZIP file was downloaded by accessing a hyperlink to a suspicious website, and the infection began when the user clicked a shortcut link file (LNK) disguised as a photo file within the ZIP archive," Trend Micro said. This triggers the execution of PowerShell that fetches and runs the JavaScript-based TONResolver malware using "node.exe," a core executable file for Node.js. The malware then connects to the C2 server obtained from the TON platform for additional attack execution and sends commands. Mamont Android Malware Dissected — An Android malware called Mamont is distributed via dropper apps masquerading as dating services to facilitate financial fraud. "The dropper and its embedded companion APK work in tandem to silently install, launch, and maintain control over the victim device while performing financial reconnaissance and awaiting attacker instructions," NCC Group said. A second variant of the malware has been found to serve phishing overlays inside Android WebView components at runtime, while also initiating phone calls, collecting installed applications, gathering device/network information, and manipulating system behavior to suppress notifications. "Additionally, it can execute commands dynamically based on input, indicating remote control functionality, and it reports execution results back through an internal handler or communication channel," security researcher Vamsi Pavuluri said. 2 Campaigns Deliver AsyncRAT — Phishing emails containing a Dropbox URL as well as macro-laced spreadsheets to distribute AsyncRAT malware. "When the recipient clicks on the link, a ZIP file is downloaded," Forcepoint said. "This file contains an Internet shortcut file in a .URL format. Opening this file leads to downloading multiple malware payloads in the background while the user is deceived by a legitimate-looking PDF opening. This file leads to a .lnk file, which then leads to a JavaScript file. This JS file links to a .BAT file, which hosts malicious content that ultimately delivers another ZIP file. This new ZIP file houses the Python script used to execute the AsyncRAT malware." The second campaign, detailed by LevelBlue, involves the use of generic emails targeting sales, procurement, and vendor management staff with a malicious spreadsheet that uses an embedded macro to download an HTA script, which then performs environment checks before delivering AsyncRAT or Remcos RAT. Clubfoot Wolf and Fluffy Wolf Targets Russia — BI.ZONE has disclosed cyber attacks mounted by an intrusion set it tracks as Clubfoot Wolf targeting a wide range of Russian sectors using spear-phishing emails to deliver NetSupport RAT to establish persistent remote access. A second threat cluster dubbed Fluffy Wolf has leveraged malicious email attachments and GitHub repository URLs to redirect recipients to ZIP archives that deliver PureLogs Stealer, PureRAT, and the Pay2Key ransomware. Also put to use in the attacks is a previously unreported C++ downloader called PowerLoader to fetch malicious PowerShell scripts from the C2 server over HTTP. In this attack chain, the loader is responsible for retrieving PureCrypter, which then launches the final payload. Multiple PhaaS Kits Spotted in the Wild — A number of phishing-as-a-service (PhaaS) toolkits have been identified: CodeStorm (which is a tenant-aware Microsoft 365 phishing kit), ARToken (a fully-featured PhaaS operator panel that shares overlaps with EvilTokens, a device code phishing toolkit), Console (for harvesting AWS console credentials), Mirage2FA (which uses short-lived HTML smuggling and obfuscated JavaScript-loaders to deliver fake Microsoft 365 login pages), and Bluekit (which uses browser-in-the-middle technique to load the legitimate login page inside an attacker-controlled browser, causing the victim to log into their accounts on the attacker's machine). At the same time, reports indicate that the Tycoon 2FA PhaaS service has resurfaced with new infrastructure and obfuscation layers following its law enforcement takedown back in March 2026. These developments also coincide with a surge in device code phishing attacks that exploit legitimate OAuth flows. Specifically, the attack tricks users into entering a device code that then issues active cookies and tokens directly to the attacker's device, bypassing multi-factor authentication (MFA). In tandem, Chinese-language phishing-as-a-service (PhaaS) communities are expanding in an area historically dominated by Russian-speaking cybercriminal groups. One such PhaaS service is the Darcula platform, linked to threat actor UNC5814, which has abandoned static phishing templates in favor of AI-powered page generators and browser automation tools, Loke Puppeteer, that can clone legitimate websites by replicating their HTML, CSS, JavaScript, and visual elements. Because each generated phishing page is unique, traditional signature-based detection methods are rendered ineffective. While PhaaS is at the core of these operations, these developers also typically offer numerous ancillary services, including the sale of personal and financial information. According to a report from Group-IB, data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. These include marketplaces like Exchange Market, Chang’An Sleepless Night, Aiqianjin, Yiqun Data, and Phoenix Overseas Resources. 🔧 Cybersecurity Tools T3MP3ST → It is an open-source offensive security framework that connects to an AI coding agent and uses it to run authorized security tests across web apps, CTF-style challenges, source code, and other targets. It provides a browser War Room and CLI for recon, exploit testing, and reporting, while its maintainers state it should only be used on systems the user owns or has written permission to test. NOX → It is an open-source Go-based tool for attack surface management, reconnaissance, and vulnerability scanning. It can run passive checks, quick probes, custom YAML workflows, or a full scan using 299 built-in modules across OSINT, subdomains, DNS, ports, web fingerprinting, and deeper vulnerability tests. Its maintainers warn that active scans make real network requests and should only be run against systems the user owns or has written permission to test. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Most of this week’s problems did not need a clever attacker so much as a useful opening. A trusted device, a trusted repo, a trusted reset path, a trusted browser feature. That word did a lot of damage. Patch what is yours. Question what looks too clean. And maybe stop assuming the boring parts are safe just because they look boring.
thehackernews.comJul 6, 2026extracted
Cybersecurity M&A Roundup: 26 Deals Announced in May 2026
Twenty-six cybersecurity-related merger and acquisition (M&A) deals were announced in May 2026. For a detailed view of the more than 420 acquisitions announced in 2025, check out SecurityWeek’s annual M&A report. Here are some of the most important cybersecurity M&A deals announced in May 2026: Akamai has agreed to acquire LayerX, a company specializing in AI and browser security, for roughly $205 million in an all-cash deal. LayerX has developed a security platform that provides real-time visibility and control over user and agentic activities across browsers, applications, and IDEs. Its technology enables Akamai to expand its Zero Trust and application security portfolio with AI usage control capabilities. Check Point Software Technologies has acquired the team and intellectual property of AI evaluation startup Deepchecks, reportedly for $10 million to $20 million. The goal of the transaction is to accelerate Check Point’s newly launched Agentic Network Security Orchestration platform. By integrating Deepchecks’ continuous monitoring and LLM evaluation technology, Check Point provides an essential validation layer for autonomous AI security agents. Cisco has announced its intent to acquire Israeli non-human identity security startup Astrix Security for an estimated $400 million. The goal of the transaction is to extend Cisco’s Zero Trust architecture to what it calls the ‘agentic workforce’. By integrating Astrix’s non-human identity management tools directly into Cisco Identity Intelligence, Duo IAM, and Splunk, Cisco plans to give security teams the ability to discover, authenticate, govern, and continuously monitor autonomous AI actors across the enterprise network infrastructure. Cycurion acquires Halo Privacy, HavenX, and Secuvant Publicly traded cybersecurity provider Cycurion, Inc. has announced the acquisition of Halo Privacy, HavenX, and Secuvant. The Secuvant deal was valued at $2.875 million, while specific purchase terms for Halo Privacy and HavenX were withheld. The unified goal of these consecutive acquisitions is to build a massive, end-to-end defense platform that combines Cycurion’s solutions with Halo’s secure communications, HavenX’s forensic attribution capabilities, and Secuvant’s automated SOC-as-a-Service workflows. Data security giant Cyera has completed the acquisition of five-month-old endpoint data protection startup Genie Security for an estimated $50 million. The transaction is designed to expand Cyera’s Data Security Posture Management (DSPM) ecosystem. By absorbing Genie Security’s endpoint telemetry agents into its platform, Cyera aims to address a critical corporate blind spot: preventing sensitive corporate data from being leaked or fed into generative AI tools and autonomous software agents. Data monetization and edge computing firm Datavault AI has entered into a binding letter of intent to acquire cybersecurity vendor CyberCatch in an all-stock transaction valued at roughly $100 million. Once finalized, CyberCatch will operate as a wholly-owned subsidiary, keeping its current management intact. The main goal of the acquisition is to bake CyberCatch’s AI-powered continuous compliance testing and automated penetration tools directly into Datavault AI’s edge GPU processing network. Industrial cybersecurity firm Dragos has acquired xIoT security specialist Phosphorus, a move aimed at strengthening its ability to help organizations secure and manage the growing number of connected devices embedded across critical infrastructure and other operational networks. Cybersecurity ratings firm SecurityScorecard has completed the acquisition of British internet scanning and threat intelligence startup Driftnet for an undisclosed sum. The primary goal of the transaction is to embed Driftnet’s high-fidelity, port-agnostic scanning capabilities into SecurityScorecard’s newly launched TITAN AI engine. Agentic security company Torq has completed the acquisition of fellow Israeli cybersecurity startup Jit for an estimated $70 million. The transaction brings Jit’s entire 30-person team under the Torq umbrella. The primary goal of the acquisition is to append Jit’s advanced AI Context Graph layer directly onto Torq’s AI SOC platform. WatchGuard acquires Perimeters.io WatchGuard Technologies has finalized the acquisition of cloud application security startup Perimeters.io. The goal of the transaction is to absorb Perimeters’ technology to power WatchGuard’s newly launched service, WatchGuard CloudDR. By merging Perimeters’ technology directly into its MSP-focused ecosystem, WatchGuard intends to give its partners a single, multi-tenant dashboard to continuously audit configurations, flag compromised credentials via ITDR, and automatically neutralize shadow AI and shadow IT risks across cloud applications. Cloud security giant Zscaler has announced its intent to acquire AI and data security firm Symmetry Systems. The goal is to bring native identity and data mapping directly into Zscaler’s Zero Trust Exchange. By integrating Symmetry Systems’ access-graph technology, Zscaler will give security teams a centralized visual control plane to track exactly what data autonomous AI agents are touching, enforce absolute least-privilege data policies, and automatically contain anomalous agent behaviors. Other cybersecurity M&A deals announced in May 2026: Boost Security acquires SecureIQx and Korbit.ai Related: Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
securityweek.comJun 8, 2026extracted
In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Threat actors poison AI chatbot queries to harvest computing power Microsoft reported that threat actors are exploiting both SEO and AI chatbot recommendations to trick users into downloading fake utilities that impersonate legitimate tools like CrystalDiskInfo and PDFgear. Once an endpoint is compromised, the attackers abuse ConnectWise ScreenConnect to secure persistent remote access and deploy a specialized binary that hollows out trusted Microsoft .NET processes. The hijacked processing power is ultimately used to run cryptocurrency miners specifically engineered to target high-performance GPUs. Grandoreiro banking trojan attacks WatchGuard researchers observed a new Grandoreiro malware campaign targeting financial institutions across Portugal and Latin America using DLL side-loading techniques that abuse four legitimate software applications. The malware has been around for a decade and it continues to be active despite law enforcement action. Self-propagating Go encryptor automates full network compromise Microsoft Threat Intelligence is tracking Storm-2697, a financially motivated group operating ‘The Gentlemen’ ransomware-as-a-service, which features an aggressive Go-based encryptor obfuscated with Garble. The malware uses password-protected command-line arguments to establish its encryption speed and automatically self-propagates across targeted networks by creating scheduled tasks with SYSTEM privileges. The Gentlemen ransomware was recently also dissected by Halcyon and Huntress. Let’s Encrypt adopts Merkle trees for post-quantum future To mitigate the massive bandwidth bloat caused by post-quantum cryptographic algorithms, Let’s Encrypt is adopting Merkle Tree Certificates to secure future web authentication infrastructure. By batching certificates under a single signature rather than authenticating them individually, this new approach significantly shrinks TLS handshake sizes while inherently baking in certificate transparency. The certificate authority plans to launch a staging environment for these optimized post-quantum certificates in late 2026, followed by a full production rollout in 2027. Federal agencies sound alarm on exposed tank gauge systems CISA, the FBI, the NSA, and other US agencies are warning critical infrastructure operators about threat actors actively exploiting internet-exposed Automatic Tank Gauge (ATG) systems used for remote liquid and fuel monitoring. Attackers are bypassing authentication and leveraging OS command execution to modify configurations, prompting the government to urge facilities to immediately disconnect ATGs from the public internet. Attacks on ATGs at US gas stations were recently linked by officials to Iran. Palantir technology chief eyed for CISA director role The Trump administration is reportedly considering Palantir Technologies Chief Technology Officer Shyam Sankar to serve as the next director of CISA. If nominated, the longtime Palantir executive would step into the vacant leadership position as CISA faces significant budget cuts. Tom Parker, a security services lead at IBM, was recently also positioned as a frontrunner for the role. Malware infection triggers leak of Ultrahuman data Indian health technology vendor Ultrahuman disclosed a data breach exposing user contact details, transaction history, and wellness metrics for a fraction of its customer base. The threat actor gained unauthorized, read-only access to an internal analytics system by leveraging credentials stolen from a malware-infected employee laptop, though the company confirmed no passwords or payment details were compromised. Crypto-miner hitches a ride on Hola Browser Sophos discovered an XMRig crypto-miner binary quietly bundled within a certified version of the Hola Browser installer for Windows. Hola attributed the anomaly to a localized supply chain compromise affecting a small segment of its distribution pipeline, which allowed the unauthorized payload to evade detection. AI attack mapping exposes rapid rise in autonomous agentic scaffolding A year-long Anthropic analysis mapping AI-enabled cyber operations against the MITRE ATT&CK framework reveals a sharp increase in threat actors leveraging LLMs for high-risk activities like lateral movement and credential dumping. The AI giant concluded that an attacker’s threat level will soon be dictated by the external agentic scaffolding they build to orchestrate autonomous attack chains. Malformed IPv6 packet triggers unpatched Comodo firewall crashes Security researcher Marcus Hutchins released details and a PoC exploit for ComoDoS, a critical vulnerability residing in Comodo Internet Security. The unpatched flaw enables remote attackers to crash targeted Windows endpoints by sending a single malformed TCP/IP packet, effectively bypassing all configured firewall rules. Hutchins said he attempted to responsibly disclose the flaw, but received no response from the vendor. SecurityWeek was unable to contact Comodo for comment.
securityweek.comJun 5, 2026extracted
Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That's according to new findings from WatchGuard and ESET, which have observed the two malware families being used to single out companies in Spain, Portugal, and Mexico, as well as mobile users in Brazil. The Grandoreiro campaign "uses the DLL Side-Loading technique abusing four different software, targeting banks in Portugal," WatchGuard researcher Euler Neto said. Active since 2016, Grandoreiro is an actively evolving banking malware that's capable of stealing credentials associated with thousands of financial institutions across 45 countries and territories. It's typically distributed via phishing emails, instructing recipients to click on sketchy links. Despite some arrests and attempts by Brazilian authorities to dismantle its infrastructure in early 2024, the malware has continued to expand its targeting footprint, while incorporating CAPTCHA checks to resist analysis. The latest campaign flagged by WatchGuard has been found to leverage DLL side-loading to launch DLLs that are developed in Delphi 11, a programming language commonly used for malware targeting the region. Two of the DLLs - mingwm10.dll and libwebp.dll - have been found to incorporate sgcWebSockets, a WebSocket and real-time communication library, for peer-to-peer (P2P) and WebRTC communications. "The DLLs associated with this case use the Session Traversal Utilities for NAT (STUN) protocol, which is a protocol that helps devices behind a NAT discover their public IP address and port number, enabling peer-to-peer communication," WatchGuard explained. "The advantage for threat actors to use web conferencing traffic in their campaigns is due to this traffic being noisy, being difficult to monitor, and due to WebRTC being commonly used across all major web-conferencing platforms." Two other DLLs associated with the campaign are libffi-6.dll and libpng15.dll, which make use of the Interactive Connectivity Establishment (ICE) protocol instead of STUN to achieve the same goal. These files specifically reference banks and financial institutions that operate in Portugal, such as Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, and Santander, among others. Also targeted are Revolut and Wise. WatchGuard also said it identified another campaign in which phishing emails are used to deliver a ZIP archive hosted on Mediafire. The file contains an obfuscated Visual Basic Script that's responsible for launching an executable, which displays a message asking users to update Adobe Reader by clicking on a button embedded in the alert. Doing so triggers a series of checks aimed at avoiding detection and complicating malware analysis, before launching the final payload to steal banking information and sensitive data. Some of the tactics overlap with a prior Grandoreiro campaign detailed by Kaspersky in October 2024. "The bigger story here is not just that Grandoreiro is still active," WatchGuard said. "It is that financially motivated threat groups continue to adapt quickly, reuse legitimate services, and hide inside traffic patterns that many organizations may already trust." "By combining phishing, DLL side-loading, WebRTC-related components, cloud service abuse, and anti-analysis checks, these campaigns show how banking malware is becoming harder to spot with surface-level defenses alone." BTMOB Offers Ready-Made Campaign Tools The disclosure coincides with a report from ESET about BTMOB, an Android remote access trojan (RAT) that first emerged in February 2025 with capabilities to unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections when certain apps are opened, and enable remote control. A subsequent iteration introduced the ability to capture Alipay PINs. "The RAT is also sold with an APK builder interface, allowing anyone to generate new payloads and adapt phishing lures for specific regions at a rapid clip - and without writing any code," ESET researcher Daniel Cunha Barbosa said. BTMOB campaigns have been mainly observed in attacks in Brazil and Latin America, but the malware's phishing-based delivery and device takeover capabilities, coupled with the ready-made app-building tooling, makes it a potent threat that poses risks well beyond the region and brings down the time and effort required to conduct a full device compromise, the Slovakian security vendor warned. The primary method through which the malware spreads is via social engineering, where users are sent links to bogus websites masquerading as streaming services, cryptocurrency mining platforms, and other trusted online services. From those sites, victims are directed to fake Google Play Store app listings that trick them into installing an Android package (APK) file containing the malware. Once installed, the malware seeks permissions to use Android's accessibility services and then leverages it to grant itself additional system access without any user interaction. BTMOB is believed to be the successor to CraxsRAT, CypherRAT, and SpySolr families. As of May 2026, the latest version of the malware (BTMOB v4.5.5) claims to offer enhanced APK protection and compatibility with the latest Google Play updates. "This update is all about speed and stability," an X profile allegedly linked to the malware posted on May 1, 2026. "We've expanded our infrastructure and refined the builder to keep you ahead of the latest mobile security patches." The Trojan is advertised by a threat actor named EVLF (@craxso) for a price tag of $700 per month. According to a YouTube video shared by the malware author on May 1, 2026, a lifetime license is worth $1,200. The complete server source code is available for $7,000, allowing customers to host the command-and-control (C2) panels on their own infrastructure. As recently as this week, the X profile also shared a link to a Medium article about "how BTMOB RAT is turning Android phones into remote-controlled weapons," and has been "evolving fast" since early 2025. "It slips in through phishing sites, grabs accessibility services, and turns your phone into a puppet," the article reads. "Hackers watch your screen live. They steal banking details. They even mine crypto in the background while you scroll Instagram." Interestingly, the article was published by an account named "CraxsRAT Main developer." The account's bio claims they are a "skilled and resourceful cybercriminal who built a profitable cybercrime enterprise by selling highly advanced RAT malware to other threat actors." The fact that BTMOB is sold under a malware-as-a-service (MaaS) model risks lowering the barrier to entry for less sophisticated threat actors. This is compounded by reports that leaked versions are already circulating on underground forums and Telegram, increasing the risk of abuse through copycats and other aspiring criminals. "Access rarely stays contained forever, and the tool can move into secondary markets through resale, barter, or sharing inside closed groups," ESET said. "Competing malware families can also copy some elements that make payload customization and campaign management easier for less skilled criminals." Italian cybersecurity company D3Lab, in an analysis of the leaked BTMOB RAT development toolkit published in December 2025, said it included the Android payload source code, its dropper, a builder environment, the operator panel for Windows, the C2 backend, and all the software dependencies required to deploy the platform. "The BTMOB leak provides a rare perspective on the inner workings of a modern Android RAT-as-a-Service ecosystem," D3Lab noted at the time. "It demonstrates that the threat actor operates not merely as a developer selling a toolkit, but as a service provider enforcing licensing, authentication, and version control over their customers."
thehackernews.comMay 27, 2026extracted
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off. Patch the quiet risks first. Let’s get into it. ⚡ Threat of the Week On-Prem Microsoft Exchange Server Exploited in the Wild—Microsoft disclosed a security vulnerability impacting on-premise versions of Exchange Server, which has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. Microsoft is providing a temporary mitigation through its Exchange Emergency Mitigation Service, while it's readying a permanent fix for the security defect. There are currently no details on how the vulnerability is being exploited, the identity of the threat actor behind the activity, or the scale of such efforts. It's also unclear who the targets are and if any of those attacks were successful. The Case for Autonomous Validation in Four On-Demand Sessions Enterprise CISOs, an industry analyst, and security leaders covered why point-in-time testing no longer matches the speed of modern threats, and how teams are using validation evidence to prioritize remediation, prove control effectiveness, and report risk to leadership. Four sessions, all on demand. Watch Now ➝ 🔔 Top News Cisco Catalyst SD-WAN Controller Flaw Under Attack—A sophisticated threat actor tracked as UAT-8616 has been attributed to the exploitation of CVE-2026-20182, a critical authentication bypass in Cisco Catalyst SD-WAN Controller. "8616 performed similar post-compromise actions after successfully exploiting CVE-2026-20182, as was observed in the exploitation of CVE-2026-20127 by the same threat actor," Cisco Talos said. "UAT-8616 attempted to add SSH keys, modify NETCONF configurations, and escalate to root privileges." UAT-8616 is the same threat actor that was behind the weaponization of CVE-2026-20127 earlier this year to gain unauthorized access to SD-WAN systems. Cisco isn't the only security vendor facing a barrage of attacks on its customers, but it is among the most heavily targeted, along with Fortinet and Ivanti. "For nation-state operators, a bug like this (as seen with the actively exploited CVE-2026-20127) is ideal for pre-positioning," Rapid7 said. "They are usually not looking for a smash and grab. They want persistence. They want access that blends in. They want to sit in the right place long enough to observe, influence, and pivot when the time is right. An SD-WAN controller is a great place to do that, because it lives in the middle of trust relationships most organizations rarely question." Blast Radius of TeamPCP Attacks Expands—A new wave of the Mini Shai-Hulud campaign compromised dozens of TanStack npm packages as part of a broader supply chain attack worming through developer ecosystems, including packages tied to UiPath, Mistral AI, OpenSearch and PyPI. The activity has been attributed to TeamPCP, which has orchestrated a series of high-profile supply chain attacks targeting popular open-source projects in recent months. The goal is the same across all attack campaigns — use poisoned, open-source software to deploy stealer malware and harvest user credentials, API keys, SSH keys, and other secrets. TeamPCP is said to be weaponizing credentials and secrets obtained in the supply chain attacks to access organizations' cloud infrastructure, not to mention turn into an initial access broker for follow-on attacks like ransomware by teaming up with other cybercrime groups. In some waves, the attackers used the Trufflehog scanner to validate those credentials. The escalating attacks show that TeamPCP prioritizes speed rather than subtlety and stealth. Supply chain attacks have become an increasingly serious concern because of the sheer scale at which trusted dependencies are reused. A single poisoned package can rapidly propagate into thousands of downstream applications, enterprise environments, and production systems. The development coincided with the compromise of the node-ipc package to distribute a stealer malware. It's currently not known who is behind the attack. Since the library is a dependency for hundreds of other packages, which in turn could be dependencies for even more packages, the attack could have cascading consequences. Apple and Google Roll Out Cross-Platform E2EE for RCS Messages—End-to-end encrypted (E2EE) Rich Communication Services (RCS) messaging is being rolled out in beta between iPhone and Android devices, closing one of the biggest interoperability gaps in mainstream mobile messaging. The feature is available to iPhone users on iOS 26.5 with supported carriers and to Android users on the latest version of Google Messages. Encrypted conversations are marked with a padlock icon in the chat interface. The wider rollout to iPadOS, macOS, and watchOS will follow in future software updates, Apple said. Instructure Reaches Ransom Agreement with ShinyHunters—Instructure, the developer of school information portal Canvas, said it struck a deal with the ShinyHunters group, which breached its systems, stole a massive amount of data, and disrupted thousands of schools that rely on the company's software. The company did not say what it had given the threat actors in exchange for the destruction of the data, but it's fair to say it likely made the controversial decision to make a ransom payment. The company said it also received "digital confirmation" that the hackers destroyed any remaining copies in the form of "shred logs." In addition, the agreement included the return of the stolen data, assurances that affected customers would not be extorted, and a commitment that individual institutions would not need to engage with the threat actor. While it remains to be seen if the threat actors will keep their side of the bargain, it's worth highlighting a key problem with paying a ransom: once attackers have a victim's data, there is no guarantee it was not copied or shared with others. As of May 12, the listing for Instructure has been removed from the ShinyHunters' data leak site. The group said: "The data is deleted, gone. The company and it's [sic] customers will not further be targeted or contacted for payment by us." Fake Hugging Face Repository Delivers Stealer Malware—A malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. The project, named Open-OSS/privacy-filter, masqueraded as its legitimate counterpart, released by OpenAI late last month (openai/privacy-filter), including copying the entire description verbatim to trick unsuspecting users into downloading it. The description accompanying the fake model diverged from the legitimate project in one aspect: instructing users to run start.bat on Windows or execute python loader.py on Linux and macOS to deploy the stealer. Access to the malicious model has since been disabled by Hugging Face. The incident highlights how public AI model registries are emerging as a new software supply chain risk for enterprises, emphasizing why AI model supply chain security needs the same level of rigor as software supply chain security. It's essential to verify publisher identity, check model card provenance, and scan for unexpected binary downloads. OpenAI Announces Daybreak—OpenAI announced Daybreak, a new initiative based on its frontier large language models (LLMs) and its artificial intelligence (AI)-powered coding assistant, Codex, to help developers secure their software from the ground up. Like Anthropic's Mythos and Project Glasswing, the initiative makes it possible to scan a codebase to identify flaws and fix them, triage vulnerability backlog and prioritize fixes by severity, impact, or exploitability, and automate vulnerability detection, validation and response. In a related development, Microsoft detailed its own AI-assisted vulnerability discovery system called MDASH, which orchestrates more than 100 specialized AI agents across multiple frontiers and distilled AI models to find vulnerabilities in the tech giant's own codebases. MDASH is designed to run a structured pipeline that goes through distinct stages: preparation, scanning, validation, deduplication, and proof construction. The emergence of Daybreak and MDASH comes amid a spike in vulnerability discovery, mainly fueled by the use of AI tools. Five months into 2026, Microsoft has already patched more than 500 vulnerabilities in its software, a rate that could see the company break its own annual record for the most number of security fixes in a year. The U.K. National Cyber Security Centre (NCSC) has also warned organizations that they should prepare for a surge of software updates driven by AI-assisted vulnerability discovery. At this stage, access to these advanced tools is tightly controlled. OpenAI has framed the access controls as a response to the dual-use nature of the underlying technology. The same AI capabilities that allow defenders to identify vulnerabilities and accelerate remediation could be misused by bad actors. Per Google, hacking groups are already using AI models to boost the speed, scale, and sophistication of their attacks, as well as perform reconnaissance and build better malware. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-42945 (NGINX Plus and NGINX Open), CVE-2026-44112 (OpenClaw), CVE-2026-42897 (Microsoft Exchange Server), CVE-2026-41096 (Microsoft Windows DNS), CVE-2026-42826 (Microsoft Azure DevOps), CVE-2026-20182 (Cisco Catalyst SD-WAN Controller), CVE-2026-44338 (PraisonAI), CVE-2026-46300, CVE-2026-46333 (Linux Kernel), CVE-2026-45185 (Exim), CVE-2026-8043 (Ivanti Xtraction), CVE-2026-44277 (Fortinet FortiAuthenticator), CVE-2026-26083 (Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS), CVE-2026-34260, CVE-2026-34263 (SAP), CVE-2026-42231, CVE-2026-42232, CVE-2026-44791, CVE-2026-44789, CVE-2026-44790, CVE-2026-42236, CVE-2026-42230 (n8n), CVE-2026-6815 (Casdoor), CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172 (dnsmasq), CVE-2026-6787, CVE-2026-6788 (WatchGuard Agent on Windows), CVE-2026-23479, CVE‑2026‑25243, CVE-2026-25588, CVE‑2026‑25589 (Redis), CVE-2026-41002, CVE-2026-40982, CVE-2026-40981, CVE-2026-41713, CVE-2026-41712, CVE-2026-41705 (Spring), CVE-2026-6722 (PHP ext-soap), CVE-2026-43824 (Argo CD), CVE-2026-27174 (MajorDoMo), CVE-2026-25254, CVE-2026-25293 (Qualcomm), CVE-2026-28819, CVE-2026-43668, CVE-2026-28972 (Apple macOS), CVE-2026-44413 (JetBrains TeamCity), CVE-2026-42010, CVE-2026-33845, CVE-2026-42009, CVE-2026-33846, CVE-2026-1584 (GnuTLS), CVE-2026-30905, CVE-2026-30906 (Zoom), CVE-2026-4782, CVE-2026-4798 (Avada Builder plugin), CVE-2026-43898 (SandboxJS), CVE-2026-8509, CVE-2026-8510 (Google Chrome), CVE-2026-44578 (Next.js), CVE-2025-14177 (PHP), CVE-2026-33439 (OpenAM), CVE-2025-66335 (Apache Doris MCP), an authentication validation bypass in Apache Pinot MCP, and an information disclosure flaw in Alibaba RDS MCP. 🎥 Cybersecurity Webinars AppSec Tools Blind to Lethal Chains: Code → Pipeline → Cloud Attacks: Your AppSec tools are drowning in alerts but completely blind to how real attackers breach you. Modern threats don’t exploit single bugs — they chain tiny weaknesses across code, pipelines, and cloud into lethal attack paths. Join the webinar to discover the 3 deadliest cross-lifecycle patterns from Wiz experts (ex-Okta/GitLab) and learn how to map & stop them. AI is making DDoS attacks dangerously intelligent. Are you ready? AI is turning DDoS attacks into smart, adaptive weapons that scan weaknesses in real-time, mimic legit traffic, and dodge traditional defenses. With a 358% surge in incidents, it's time to upgrade your strategy. Join the webinar to learn the latest tactics and how to defend effectively. 📰 Around the Cyber World Flaw in Apple's Memory Integrity Enforcement —Calif said it discovered a new way of circumventing Apple's Memory Integrity Enforcement (MIE), a new hardware-assisted memory safety system, and achieved privilege escalation. The discovery was made possible while testing an early version of Anthropic's Mythos Preview in April. "It's the first public macOS kernel memory corruption exploit on M5 silicon, surviving MIE," Calif said. "The exploit is a data-only kernel local privilege escalation chain targeting macOS 26.4.1 (25E253). It starts from an unprivileged local user, uses only normal system calls, and ends with a root shell. The implementation path involves two vulnerabilities and several techniques, targeting bare-metal M5 hardware with kernel MIE enabled." Additional details are currently withheld to give Apple time to address the issues. Mustang Panda Delivers Updated FDMTP Tool —A new campaign consistent with tradecraft associated with Mustang Panda has been observed targeting the Asia-Pacific and Japan (APJ) region to deliver an updated version of FDMTP using DLL side-loading. The malware is designed to connect to an external server and receive commands from the remote server, profile compromised hosts, and load additional plugins to handle scheduled tasks, manage Windows Registry persistence, or retrieve files or commands. The activity has been spotted since September 2025. New Flaw in Burst Statistics Plugin Exploited —Threat actors are exploiting a critical flaw in the Burst Statistics WordPress plugin (CVE-2026-8181, CVSS score: 9.8), which "allows unauthenticated attackers who know a valid administrator username to fully impersonate that administrator for the duration of any REST API request, including WordPress core endpoints such as /wp-json/wp/v2/users, by supplying any arbitrary and incorrect password in a Basic Authentication header," per Wordfence. An attacker could exploit this flaw to create a new administrator-level account with no prior authentication and seize control of the site. The plugin has over 200,000 installations. Wordfence said it has blocked thousands of attacks targeting this vulnerability. CISA and Others Release Guidance to Strengthen AI Supply Chain —Multiple government cyber agencies issued a joint guidance to help public and private sector stakeholders improve transparency in their AI systems and supply chains. "A software bill of materials (SBOM) acts as an 'ingredients list' for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems," the agencies said. "Because AI systems are software systems, these recommendations should be considered in addition to the general minimum elements for an SBOM." Stealer Malware Continues to Evolve —Cybersecurity researchers disclosed details of various new and emerging information stealers like Salat, Gremlin, and Reaper, the last of which is a new SHub macOS stealer variant that spoofs Apple, Google, and Microsoft across a multi-stage attack chain to steal credentials, exfiltrate business files, and establish persistent backdoor access. "Reaper uses fake WeChat and Miro installers as lures," SentinelOne researcher Phil Stokes said. "The payload may be hosted on a typo-squatted Microsoft domain, executed under the guise of an Apple security update, and persist from a fake Google Software Update directory." Unlike other macOS stealers that trick users into opening and pasting malicious commands into the Terminal app, Reaper relies on the applescript:// URL scheme to trigger the execution of a malicious AppleScript, thereby bypassing Terminal-based mitigations Apple introduced in late March 2026. According to a report published by Flare.io last week, one in four infostealer victims has active access to corporate infrastructure: VPN credentials, SaaS sessions, cloud platforms. "One in six gaming-related infections involves a user with corporate infrastructure access," it said. "16% of victims infected through gaming lures also held active credentials for VPNs, SaaS platforms, or cloud environments, creating a direct pipeline from personal device use to enterprise compromise." Flaws in myAudi Platform —Multiple security flaws have been discovered in the myAudi connected car platform, allowing anyone with knowledge of a vehicle's VIN to add it to their account as a guest and access sensitive data. The leaked information included the embedded SIM's IMEI and ICCID identifiers, the GPS location of the primary owner when they triggered a "honk & flash" command, and vehicle lock status. One of the identified issues has been fixed by Audi and CARIAD. 🔧 Cybersecurity Tools Rustinel → It is an open-source endpoint detection tool for Windows and Linux. It collects system activity using ETW on Windows and eBPF on Linux, checks events against Sigma rules, YARA rules, and IOCs, and writes alerts in ECS NDJSON format for use in SIEM or log pipelines. It is built for blue teams, detection engineers, researchers, and testing environments, not as a full replacement for commercial EDR. Giskard → It is an open-source Python tool for testing and evaluating LLM agents and AI systems. It helps developers check whether an AI app behaves correctly, stays grounded in context, follows safety rules, and handles multi-turn conversations reliably. Its current version focuses on lightweight evaluation workflows, while related scanning and RAG evaluation features are still being developed or are available in older versions. VanGuard → It is a cross-platform incident response toolkit for Windows and Linux that lets security teams collect evidence, run triage, perform threat hunting, capture memory, gather disk artifacts, manage Velociraptor workflows, and generate reports from a single portable binary without installation. It includes 28 pre-built investigation workflows, supports offline use, and tracks evidence with hashing, chain of custody, and audit logging. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion The message is simple: trust less, check more. Bad packages, fake pages, weak plugins, leaked keys, and old bugs all lead to the same place. Patch first. Rotate keys. Review what you run in prod. That’s the work. That’s the recap.
thehackernews.comMay 18, 2026extracted
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. "External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks," Ivanti said in an advisory. Fortinet published advisories for two critical shortcomings affecting FortiAuthenticator and FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that could result in code execution - CVE-2026-44277 (CVSS score: 9.1) - An improper access control vulnerability in FortiAuthenticator that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. (Fixed in FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3) CVE-2026-26083 (CVSS score: 9.1) - A missing authorization vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI that may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. (Fixed in FortiSandbox versions 4.4.9 and 5.0.2, FortiSandbox Cloud version 5.0.6, and FortiSandbox PaaS versions 4.4.9. and 5.0.2) SAP also shipped fixes for two critical vulnerabilities - CVE-2026-34260 (CVSS score: 9.6) - An SQL injection vulnerability in SAP S/4HANA CVE-2026-34263 (CVSS score: 9.6) - A missing authentication check in the SAP Commerce cloud configuration "The vulnerability is caused by an overly permissive security configuration with improper rule ordering, allowing an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution," Onapsis said about CVE-2026-34263. On the other hand, CVE-2026-34260 could be exploited by an attacker to inject malicious SQL statements and potentially impact the confidentiality and availability of the application. However, since the affected code only allows read access to data, the vulnerability does not compromise the integrity of the application. "It allows a low-privileged, authenticated attacker to inject malicious SQL code via user-controlled input, potentially exposing sensitive database information and crashing the application," Pathlock said. Patches have also been released by Broadcom for a high-severity flaw in VMware Fusion (CVE-2026-41702, CVSS score: 7.8) that could pave the way for local privilege escalation. The issue has been addressed in version 26H1. "VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary," Broadcom said. "A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed." Round off the list is a set of five critical vulnerabilities impacting n8n - CVE-2026-42231 (CVSS score: 9.4) - A vulnerability in the xml2js library used to parse XML request bodies in n8n's webhook handler that allows prototype pollution via a crafted XML payload, enabling an authenticated user with permission to create or modify workflows to achieve remote code execution on the n8n host. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-42232 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node, leading to remote code execution when combined with other nodes exploiting the prototype pollution. (Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1) CVE-2026-44791 (CVSS score: 9.4) - A bypass for CVE-2026-42232 that could result in remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44789 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node, leading to remote code execution on the n8n host. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) CVE-2026-44790 (CVSS score: 9.4) - An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation, enabling an attacker to read arbitrary files from the n8n server and resulting in full compromise. (Fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1) Software Patches from Other Vendors Security updates have also been released by other vendors over the past several weeks to rectify various vulnerabilities, including - ABB Adobe Amazon Web Services AMD Apple ASUS Atlassian Axis Communications AVEVA Canon Cisco CODESYS ConnectWise Dell Devolutions Drupal F5 Fortra Foxit Software Fujitsu GitLab GnuTLS Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Intel Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Meta WhatsApp Microsoft Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA OPPO Palo Alto Networks Phoenix Contact Phoenix Technologies Progress Software QNAP Qualcomm React Ricoh Samsung Schneider Electric Siemens Sophos Spring Framework Supermicro Synology Tenable TP-Link WatchGuard Zoom, and Zyxel
thehackernews.comMay 18, 2026extracted
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories
You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. Attacking the systems behind apps is easier than breaking the apps themselves. The exploits are simple but still work, giving attackers easy access. AI tools are also part of the problem now. They trust bad input and take real actions, which makes the damage bigger. Then there are quieter issues. Apps take data they should not. Devices behave in strange ways. Attackers keep testing what they can get away with. No noise. Just ongoing damage. Here is the list for this week’s ThreatsDay Bulletin. State-backed crypto heistInter-blockchain communication protocol LayerZero has revealed that North Korean threat actors tracked TraderTraitor may have been behind the recent hack of decentralized finance (DeFi) project KelpDAO, resulting in the theft of $290 million. "The attack was specifically engineered to manipulate or poison downstream RPC infrastructure by compromising a quorum of the RPCs the LayerZero Labs DVN relied upon to verify transactions," LayerZero said. KelpDAO, in a post on X, said, "Two RPC nodes hosted by LayerZero were compromised. A simultaneous DDoS attack was launched against the third RPC node. This was an attack on LayerZero's infrastructure. Kelp's own systems were not involved in building or operating that infrastructure." Meanwhile, the Arbitrum Security Council has temporarily frozen the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. In an analysis published today, Chainalysis said: "Crucially, this was not a smart contract hack, but a sophisticated attack on off-chain infrastructure. The attackers compromised internal RPC nodes and DDoS’d external nodes to feed false data to a single-point-of-failure verification network (a 1-of-1 DVN setup). This tricked the Ethereum contract into releasing funds based on a phantom token 'burn' on the source chain." It's worth noting that TraderTraiter was attributed to the mega Bybit hack in early 2025 that led to the theft of $1.5 billion in digital assets. Recently, Lazarus Group was also linked to the $285 million theft from the Drift Protocol. Active RCE exploitsSeparately, VulnCheck has warned of attacks attempting to exploit two flaws in MajorDoMo, a smart home automation platform. While CVE-2026-27175 is a critical command injection vulnerability that started seeing exploitation on April 13, CVE-2026-27174 allows unauthenticated remote code execution via the PHP console in the admin panel and was first detected on April 18. "CVE-2026-27175 was exploited to drop a PHP webshell that delivers persistent backdoor access," VulnCheck said. "CVE-2026-27174 saw exploitation that ended in a Metasploit php/meterpreter/reverse_tcp staged payload." Other vulnerabilities that have witnessed exploitation efforts include CVE-2025-22952, an SSRF in Elestio Memos, and CVE-2024-57046, an authentication bypass in NETGEAR DGN2200 routers. Supply chain malware surgeA number of malicious packages have been discovered in the npm registry: ixpresso-core, forge-jsx, @genoma-ui/components, @needl-ai/common, rrweb-v1, cjs-biginteger, sjs-biginteger, bjs-biginteger, @fairwords/websocket, @fairwords/loopback-connector-es, @fairwords/encryption, js-logger-pack, and @kindo/selfbot. These packages come with features to steal sensitive data from compromised hosts, perform system reconnaissance, andimplant an SSH backdoor by injecting the attacker's public key into ~/.ssh/authorized_keys, deliver an information stealer, and spread the XWorm remote access trojan (RAT). The packages published under the "@fairwords" scope have also been found to self-propagate to all npm packages using the victim's token and attempt cross-ecosystem propagation to PyPI via .pth file injection. New versions of js-logger-pack have since been found to leverage the Hugging Face repository to poll for updates and use it as a data-theft destination. Also detected was the compromise of @velora-dex/sdk (version 9.4.1) to decode and execute a Base64 payload that fetches a shell script from a remote server that, in turn, downloads and persists a Go-based remote access trojan called minirat on macOS systems. Another legitimate package to be compromised was mgc (versions 1.2.1 through 1.2.4), which was injected with a dropper that detects the operating system and fetches a platform-specific RAT from a GitHub Gist to exfiltrate valuable data. AI prompt injection surgeForcepoint has detected 10 new indirect prompt injection (IPI) payloads targeting artificial intelligence (AI) agents with malicious instructions designed to achieve financial fraud, data destruction, API key theft, and AI denial-of-service attacks. "Regardless of the specific payload technique or attacker intent, every case follows the same fundamental sequence: the attacker poisons web content, hides the payload from human view, waits for an AI agent to ingest the page, exploits the LLM's inability to distinguish trusted instructions from attacker-controlled content, and triggers a real-world action with a covert exfiltration return channel back to the attacker," the company said. Covert browser data accessThe Claude desktop app has been found granting itself permission to access web browser data, even if some browsers haven't even been installed on a user's computer, web privacy expert Alexander Hanff said. The app has been spotted placing configuration files in preset locations for Chromium-based browsers like Brave, Google Chrome, Microsoft Edge, and Vivaldi. The Native Messaging manifest files pre-authorize Claude to interact with the browser even before the user installs it. The issue has been described as a case of dark pattern that violates privacy laws in the E.U. Hardware display protectionThe U.K. National Cyber Security Centre (NCSC) has unveiled a new technology called SilentGlass that's designed to protect video connections from cyber attacks. "SilentGlass, a plug-and-play device, actively blocks anything unexpected or malicious between HDMI and Display Port connections and screens," NCSC said. "Already successfully deployed on Government estates, SilentGlass is now available for anyone to buy and use. It has been approved for use in the most high-threat environments." Passkeys replace passwordsIn a related development, the NCSC also endorsed passkeys as the default authentication standard and the "first choice of login" for access to all digital services. "Passkeys are a newer method for logging into online accounts, which do much of the heavy lifting for users, only requiring user approval rather than needing to input a password," NCSC said. "This makes passkeys quicker and easier to use and harder for cyber attackers to compromise." It also said the majority of cyber harms to individuals begin with criminals stealing or compromising login details, which makes passkey adoption a "huge leap" in boosting resilience to phishing attacks. More than 50% of active Google services users in the U.K. are said to be already using passkeys. Backdoor sabotage claimsReports from Iranian media have claimed that hardware made by Cisco, Juniper, Fortinet, and MikroTik either rebooted or disconnected during recent attacks on Iran, despite the country being cut off from the global internet. "The most striking and suspicious aspect of this incident is its precise timing and the lack of access to the international internet at that moment," Iranian news website Entekhab said. "This disruption occurred at a time when international gateways were effectively blocked or inaccessible; therefore, attributing this chain collapse to 'a simple cyber attack from beyond the borders' is not only unconvincing but also reveals the traces of deep-seated sabotage embedded within the equipment." The report hypothesizes the presence of hidden firmware backdoors or rogue implants within compromised devices, creating a dormant botnet that's activated when a certain event occurs without the need for internet access. The other possibility is a supply chain compromise. "If the chips or installation files of Cisco and Juniper products are compromised before entering the country, even replacing the operating system will not solve the problem, because the root of the problem is embedded in the hardware and read-only memory (ROM)," the report said. These arguments have found purchase in China, whose state media agency Xinhua called U.S.-made equipment the "real trojan horse." The disclosure comes as DomainTools revealed that the various hacktivist personas adopted by Iran, such as Homeland Justice, Karma, and Handala, "constitute a coordinated, MOIS-aligned cyber influence ecosystem operating under multiple branded identities that serve distinct but complementary operational roles." Ransomware infighting escalatesThe Krybit ransomware group has hacked the website of rival ransom group 0APT after the latter threatened to dox Krybit's members. According to security firm Barricade, 0APT leaked the complete database of the Krybit ransomware operation, including victim records, plaintext credentials, Bitcoin wallets, encryption tokens, and a 56MB exfiltration file inventory. In return, Krybit has hit back by compromising 0APT's server within 48 hours, defacing their data leak site, and publishing source code, bash history, Nginx logs, and system files. To rub salt into the wound, the group listed 0APT as victim #1 on their own leak site. Stealth malware-as-a-serviceThere is a new cryptor-as-a-service platform called FUD Crypt (fudcrypt[.]net). "For $800 to $2,000 per month, subscribers upload an arbitrary Windows executable and receive a multi-stage deployment package that attempts automatic DLL sideloading, in-memory AMSI and ETW interference, silent UAC elevation via CMSTPLUA, and Windows Defender tamper via Group Policy on Enterprise builds," Ctrl-Alt-Intel said. Formbook phishing surgeTwo different phishing campaigns targeting Greek, Spanish, Slovenian, Bosnian, Latin, and Central American companies are using different techniques to deliver Formbook malware. "FormBook is a data-stealing malware that targets Windows systems, primarily distributed through phishing emails with malicious attachments," WatchGuard said. “It collects sensitive information like login credentials, browser data, and screenshots, using advanced evasion techniques to avoid detection.” Stealth .NET execution abuseA highly sophisticated, multi-stage post-exploitation framework has been observed targeting organizations in the Middle East and EMEA financial sectors. "The threat actor leverages a legitimate, digitally signed Intel utility (IAStorHelp.exe) by abusing the .NET AppDomainManager mechanism, effectively turning a trusted binary into a stealthy execution container," CYFIRMA said. "This approach allows malicious code to be executed within a trusted environment. It bypasses conventional security controls without modifying the original signed binary." Because AppDomainManager hijacking enables stealth execution within a trusted signed binary, it allows malicious code to run without modifying the original executable, effectively bypassing code-signing trust controls. The attack begins with a phishing email containing a ZIP archive, which contains an LNK file masquerading as a PDF document to execute "IAStorHelp.exe." It's currently not known who is behind the campaign, but the level of sophistication, modular design, and operational discipline suggest capabilities consistent with advanced threat actors. RAT plus adware bundleA new malware campaign is spreading both a remote access trojan and adware together, allowing attackers to establish persistent access and make financial profits. The attack has been found to leverage a loader to deliver Gh0st RAT trojan and CloverPlus adware, an unwanted software designed to install advertising components and change browser behavior, such as startup pages and pop-up ads, per Splunk. macOS stealth execution abuseIn a new analysis, Cisco Talos revealed that bad actors can bypass security controls in Apple macOS by repurposing native features like Remote Application Scripting (RAS) for remote execution and abusing Spotlight metadata (Finder comments) to stage payloads in a way that evades static file analysis. "Because Finder is scriptable over RAE, the comment of a file on a remote machine can be set via the “eppc://” protocol. By Base64 encoding a payload locally, a multi-line script can be stored within this single string field. The make new file command handles the creation of the target file, ensuring that no pre-existing file is required," Talos said. "The payload resides entirely within the Spotlight metadata, a location that remains largely unexamined by standard endpoint detection and response (EDR) solutions. This creates a stealthy staging area where malicious code can persist on the disk without triggering alerts associated with suspicious file contents." In addition, attackers can move toolkits and establish persistence using built-in protocols such as SMB, Netcat, Git, TFTP, and SNMP operating entirely outside the visibility of standard SSH-based telemetry. In some cases, adversaries can also bypass built-in restrictions by using Terminal as a proxy for execution, encoding payloads in Base64 and deploying them in stages. LLM agent testing frameworkA group of academics has released a hackable, modular, and configurable open-source framework called Terrarium for studying and evaluating decentralized LLM-based multi-agent systems (MAS). "As the capabilities of agents progress (e.g., tool calling) and their state space expands (e.g., the internet), multi-agent systems will naturally arise in unique and unexpected scenarios," the researchers said, adding it acts as "an isolated playground for studying agent behavior, vulnerabilities, and safety. It enables full customization of the communication protocol, communication proxy, environment, tool usage, and agents." AI data privacy purgeAccording to Reuters, AI company Clarifai said it has deleted 3 million profile photos taken from dating site OkCupid in 2014. It follows a settlement reached last month between the U.S. Federal Trade Commission (FTC) and Match Group, OkCupid's owner. Clarifai is said to have certified the data deletion to the FTC on April 7, 2026, and deleted any models that trained on the data. The company also emphasized that it hadn't shared the data with third parties. The FTC opened the investigation in 2019, after The New York Times reported that Clarifai had built a training database using OkCupid dating profile photos. The behavior was a direct violation of OkCupid's privacy policy, although Clarifai was not accused of wrongdoing. Zero-credential RCE chainVulnCheck said it's seeing active exploitation of the Apache ActiveMQ Jolokia remote code execution chain that strings together CVE-2026-34197 and CVE-2024-32114. "CVE-2024-32114 removes authentication from the Jolokia endpoint entirely on ActiveMQ versions 6.0.0 through 6.1.1," VulnCheck's Jacob Baines said. "Combined with CVE-2026-34197, that is zero-credential RCE." Stealth phishing lureThere has been a surge in phishing emails utilizing empty subject lines as a way to lure users to actually click and open the email without the usual warning cues. Known as silent subject or null subject phishing, the technique is designed to exploit blind spots in email defenses, as it allows such emails to bypass security filters that rely on analyzing the subject lines for specific keywords that may indicate potential phishing or scam. "Emails with empty subject lines evade user suspicion by exploiting human curiosity," CyberProof said. "The primary objective of a silent subject campaign is to gain initial access through social engineering, leading to credential compromise, unauthorized access, and potential lateral movement within targeted environments, especially focusing on high-value or VIP users." Industrial-scale SIM farmsA Belarus-based turnkey solution is assisting SIM farm operators in supporting cybercrime on an industrial scale. Infrawatch said that it identified 87 instances of ProxySmart control panels in 17 countries that are linked to at least 24 commercial proxy providers and 35 cellular providers. The footprint spans 94 phone farm locations, distributed across 19 U.S. states, as well as countries in Europe and South America. ProxySmart provides an end-to-end platform for operating and monetizing mobile proxy infrastructure, including farm management, device control, customer provisioning, retail proxy sales, and payment handling. It's accessible via a web-based control panel that's self-hosted by the farm operator. Devices in the farms are either physical Android phones or USB 4G/5G modems. The phones are enrolled via an unsigned Android APK package downloaded from the ProxySmart website, with SMS send and receive capability included. Modems are managed through ModemManager, an open-source USB dongle management tool. The ProxySmart service is written in Python and obfuscated using PyArmour. "ProxySmart is publicly associated with a Belarus-based vendor footprint and offers an end-to-end stack for operating and monetizing a physical farm, including device management, automated IP rotation, customer provisioning, plan enforcement, and anti-bot countermeasures," the company said. "Technical analysis indicates operator capabilities consistent with large-scale evasion enablement, including automated IP rotation, remote device control, and network fingerprint spoofing." SIM farms enable a range of cybercrime activity such as smishing, premium-rate number fraud, bot sign-ups, and one-time password interception. In response to the findings, ProxySmart disputed its characterization as a SIM farm, stating it's a "data-path proxy management platform" and that its mobile proxy infrastructure "underpins a wide range of legitimate commercial and research activity" including advertising verification, brand protection, price monitoring, and anti-fraud model training, among others. Telegram under CSAM probeOfcom, the U.K.'s independent communications regulator, has launched an investigation into Telegram under the country's Online Safety Act to examine whether the platform is being used to share child sexual abuse material (CSAM) and is doing enough to combat the threat. "We received evidence from the Canadian Centre for Child Protection regarding the alleged presence and sharing of child sexual abuse material on Telegram, and carried out our own assessment of the platform," Ofcom said. "In light of this, we have decided to open an investigation to examine whether Telegram has failed, or is failing, to comply with its duties in relation to illegal content." In a statement shared with The Record, Telegram said it "categorically denies Ofcom's accusations," adding it has "virtually eliminated the public spread of CSAM on its platform through world-class detection algorithms and cooperation with NGOs." Earlier this year, Ofcom also commenced a probe into X to determine whether the service is taking necessary steps to take down illegal content, including non-consensual intimate images and CSAM. EU cracks disinfo opsThe European Union imposed sanctions on two pro-Russian organizations accused of spreading disinformation and supporting the Kremlin's hybrid influence operations against Europe and Ukraine. The measures target Euromore and the Foundation for the Support and Protection of the Rights of Compatriots Living Abroad (Pravfond). The move is part of the E.U.'s broader effort to counter Russian information and influence operations targeting Europe since the start of Moscow's full-scale invasion of Ukraine in 2022. The E.U. has imposed sanctions on 69 individuals and 19 entities linked to Russian hybrid warfare. Bot farm dismantledUkrainian authorities have dismantled a bot farm that's alleged to have supplied thousands of fake social media accounts to Russian intelligence services for use in disinformation campaigns against Ukraine. The suspected organizer of the network has been detained in the northern city of Zhytomyr, and nearly 20,000 fraudulent online profiles that were used in information operations have been blocked. The suspect is believed to have sold more than 3,000 fake Telegram accounts each month to Russian clients. The accounts were created using Ukrainian mobile phone numbers and then advertised on online platforms used by pro-Russian actors. If convicted, the suspect faces up to six years in prison. Malicious extensions surgeMore than 130,000 users have downloaded and installed malicious Chrome and Edge extensions that, while offering the promised functionality, also implement covert tracking, remote configuration capabilities, and data collection mechanisms.The 12 extensions posed as tools to download TikTok videos and were available through the official Chrome and Edge stores. The activity has been codenamed StealTok. The extensions have been found to use remote configuration to bypass store review. "Beyond privacy concerns, the use of remote configuration endpoints introduces a significant security risk, enabling post-installation behavior changes that bypass marketplace review mechanisms," LayerX said. Joomla SEO spam backdoorIn a new campaign spotted by Sucuri, threat actors are planting a new PHP-based backdoor on Joomla sites to inject SEO spam. The injected script acts as a remote loader to send information about the infected website and awaits further instructions from an attacker-controlled server. "Attackers inject malicious code that silently serves spam content to visitors and search engines, all without the site owner knowing," Sucuri said. "The goal is simple: abuse the site's reputation to push traffic towards products the attacker wants to promote." Post-exfiltration data tradeA new service called Leak Bazaar has been promoted on the Russian-speaking TierOne forum that claims to process data stolen from extortion and ransomware attacks and turn it into "something more legible, more selective and precise, and making it marketable for the general population to ingest." It's advertised by a user named Snow, who joined the forum on March 3, 2026. "What Leak Bazaar is really offering is not a DLS or Data or Dedicated Leak Site in the conventional sense, but a post-exfiltration service layer," Flare said. "It is trying to reassure both suppliers and buyers that the platform can solve the most frustrating part of data theft, which is that a large percentage of exfiltrated material is too noisy, too unstructured, or too cumbersome to use without additional labor." RDP scanning concentrationGreyNoise has disclosed that a small cluster of 21 IP addresses is now responsible for generating nearly half of all the RDP scanning traffic on the public internet. The addresses are registered to ColocaTel (AS213438), a company based in the Seychelles. According to the threat intelligence firm, mass internet scanning activity is now preceding vendor vulnerability disclosures more frequently than before, with 49% of surges arriving within 10 days of disclosure and 78% within 21 days.In a related development, security researcher Morgan Robertson revealed that almost three-quarters of Perforce P4 source code management servers connected to the internet are misconfigured and leaking source code and sensitive files. "The default Perforce settings allow unauthenticated users to create accounts, list existing users, access passwordless accounts, and, until version 2025.1, allowed syncing repositories remotely; potentially exposing intellectual property across more than a dozen sectors, including gaming, healthcare, automotive, finance, and government," Robertson said. "Action is recommended for all Perforce administrators to ensure security hardening, including setting stronger authentication requirements, disabling automatic account creation, and raising security levels." Emerging threat groups surgeVarious new hacktivist, data extortion, and ransomware crews have been spottedin the wild. These include Harakat Ashab al-Yamin al-Islamia, World Leaks, Lamashtu, Payouts King, BravoX, Black Shrantac, NBLOCK, Ndm448, Chip, Ransoomed, and Zollo. None of this is new. That is the problem. Old paths still open, basic checks still skipped, and trust still given where it should not be. Attackers are not doing anything magical, they are just faster and less careful because they do not need to be. The fixes are known but ignored. Patch early, check what you install, limit access, and stop trusting inputs by default. Most of the damage comes from things that were easy to prevent. Same story next week.
thehackernews.comApr 23, 2026extracted
Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection
Two phishing campaigns, each using a different stealthy infection technique, are targeting organizations in attacks which aim to deliver data stealing malware to devices running on Microsoft Windows. The goal of the campaigns is to install Formbook, a notorious form of infostealer which has been available as part of malware-as-a-service schemes since 2016. The infostealer malware is designed to gather sensitive information including login credentials, browser data and screenshots. It is also equipped with advanced evasion techniques to avoid detection. Ten years on from its initial release, Formbook is still an active cyber threat to organizations across a range of industries, with no sign of slowing down. Cybersecurity threat researchers at WatchGuard have detailed at least two new Formbook campaigns. As detailed in a blog post published on April 20, Formbook campaigns have been spotted targeting companies in Greece, Spain, Slovenia, Bosnia, Croatia and a range of countries in South America. The phishing lures appear to be disguised as common forms of business emails. “What makes these campaigns especially noteworthy is not just the malware itself, but the diversity of methods used to evade detection and abuse legitimate software and trusted system processes,” said Watchguard. DLL Sideloading and Obfuscated JavaScript Both Formbook campaigns begin with phishing emails, but use different methods to hide and deliver the malware payload: one uses dynamic-link library (DLL) sideloading and while the other uses obfuscated JavaScript The first campaign begins with a phishing email which uses an RAR file containing four files: three of them are DLLs, and one of them is a Windows Executable file (EXE). By using DLL sideloading, a technique deployed by attackers which is used to execute malicious code by tricking a program into loading a harmful DLL instead of a legitimate one, the attackers can run a malicious payload while avoiding the system identifying it as malicious or unusual. Meanwhile, a second campaign utilizes a different tactic for delivering Formbook malware. The initial stage is once again a phishing email, but this time the malicious payload is hidden inside JavaScript and PDF files, which uses obfuscated code to help it hide from detection. When executed, the JavaScript drops two image files, which in turn drop PowerShell commands, obfuscated within long strings of code, which are ultimately used to run a Windows executable, which deploys a custom malware loader. Forms of malware which have previously been identified as being distributed by this loader include Remcos, XWorm, AsyncRAT, and SmokeLoader. In this instance it is being used to distribute the same Formbook malware which is delivered by the first phishing campaign. “Security teams should monitor for suspicious archive-based email attachments, anomalous DLL loading behavior, PowerShell execution tied to user-opened attachments, and signs of manual DLL mapping or direct syscall activity in memory,” advised WatchGuard. “By correlating these behaviors across the attack chain, organizations can improve their ability to detect and stop FormBook infections before sensitive data is compromised,” the company added.
infosecurity-magazine.comApr 20, 2026extracted
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands. "The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an advisory. In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content. "Manipulated planning figures, broken reports, or deleted consolidation data can undermine close processes, executive reporting, and operational planning," Pathlock said. "In the wrong hands, this issue also creates a credible path to both stealthy data theft and overt business disruption." Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild. That said, there are many unknowns at this stage. It is not clear how many people have been affected by the hacking campaign. Nor is there any information about who is behind the activity, who is being targeted, and what their motives could be. Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass. The vulnerabilities are listed below - CVE-2026-34619 (CVSS score: 7.7) - A path traversal vulnerability leading to security feature bypass CVE-2026-27304 (CVSS score: 9.3) - An improper input validation vulnerability leading to arbitrary code execution CVE-2026-27305 (CVSS score: 8.6) - A path traversal vulnerability leading to arbitrary file system read CVE-2026-27282 (CVSS score: 7.5) - An improper input validation vulnerability leading to security feature bypass CVE-2026-27306 (CVSS score: 8.4) - An improper input validation vulnerability leading to arbitrary code execution Fixes have also been released for two critical FortiSandbox vulnerabilities that could result in authentication bypass and code execution - CVE-2026-39813 (CVSS score: 9.1) - A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. (Fixed in versions 4.4.9 and 5.0.6) CVE-2026-39808 (CVSS score: 9.1) - An operating system command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. (Fixed in version 4.4.9) The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that could allow an attacker to view sensitive information. The company said it's being actively exploited, although there are no insights into the in-the-wild exploitation associated with the bug. "SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made," Kev Breen, senior director of threat research at Immersive, said. "A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Apple ASUS AVEVA Broadcom (including VMware) Canon Cisco Citrix CODESYS D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal Elastic F5 Fortinet Foxit Software FUJIFILM Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) Huawei IBM Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric MongoDB Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NETGEAR Node.js NVIDIA ownCloud Palo Alto Networks Phoenix Contact Progress Software QNAP Qualcomm Rockwell Automation Ruckus Wireless Samsung Schneider Electric Siemens SonicWall Splunk Spring Framework Supermicro Synology TP-Link WatchGuard, and Xiaomi
thehackernews.comApr 15, 2026extracted
World Backup Day 2026, il dato fa parte della nostra identità digitale: come proteggerlo
Il World Backup Day si celebra ogni anno il 31 marzo per sensibilizzare l’opinione pubblica sull’importanza di proteggere i dati digitali, le foto e i file dalla perdita causata da ransomware, furti o guasti hardware. Ci ricorda “la centralità del dato per la nostra società” in cui “i dati sono il cuore di ogni attività digitale, ma con un’evoluzione tecnologica sempre più rapida i processi a loro protezione si dimostrano sempre più fragili e vulnerabili”, secondo Pierluigi Paganini, analista di cyber security e Ceo Cybhorus.. In un Paese come l’Italia, in cui si registrano 433 attacchi in 30 giorni, secondo l’ultimo report CERT-AgID, questa ricorrenza rappresenta un’occasione per ricordare l’importanza di adottare pratiche sicure per la gestione dei dati, come la regola del 3-2-1, oggi 3-2-1-0. “Il backup dei dati si è evoluto da semplice attività IT a requisito fondamentale per la resilienza aziendale e informatica”, commenta Corey Nachreiner, Chief security officer di WatchGuard Technologies. “Nel contesto attuale”, secondo Francesco Iezzi, Cybersecurity Specialist NHOA, “il World Backup Day assume un significato ancora più concreto. Viviamo circondati da un ecosistema digitale dove intelligenza artificiale e nuove tecnologie ci supportano, ci accelerano e, in alcuni casi, ci sostituiscono in attività che un tempo erano esclusivamente umane”. Ecco le best practice per mettere al sicuro i dati, l’asset più prezioso di un’azienda insieme al capitale umano, perché “l’essere umano nasce con la paura del vuoto”, come ci ricorda Domenico Raguseo, Head of CyberSecurity & (Digital) Infrastructure Exprivia, mentre “la specie umana non ha avuto ancora tempo per comprendere i rischi associati all’ecosistema digitale“. Invece dobbiamo imparare la lezione e renderla una routine quotidiana. “Se il backup resta un pilastro fondamentale, l’evoluzione del panorama delle minacce impone alle aziende di ampliare lo sguardo verso concetti più ampi come recovery e resilienza, nonché verso la capacità di ripristinare le operazioni in modo affidabile dopo un incidente”, secondo Sean Deuby, Principal Technologist, Semperis. Infatti “il backup perfetto non è quello che esiste, ma quello che si ripristina”, conferma Sandro Sana, Ethical Hacker e membro Comitato Scientifico Cyber 4.0. Indice degli argomenti rotezione digitale Secondo i risultati della ricerca “Protezione digitale e cybersecurity”, condotta da Europ Assistance Italia, in collaborazione con Lexis Research, il nove italiani su dieci navigano online almeno una volta al giorno mentre l’80% usa sistemi di messaggistica istantanea o social network. “In un contesto in cui il digitale è una componente sempre più presente nella nostra vita privata e professionale – e in cui l’utilizzo crescente dell’intelligenza artificiale rende gli attacchi informatici ancora più sofisticati e difficili da intercettare -, la cyber security diventa una necessità. Nessuno oggi può considerarsi davvero immune”, dichiara Erika Delmastro, Chief Commercial Officer di Europ Assistance Italia. Il 71% ha impiegato almeno una volta l’intelligenza artificiale, metà la utilizza almeno una volta a settimana e il 27% su base quotidiene. Il 44% ne è intimorito per assenza di controllo umano. Però scende la consapevolezza dei rischi cyber e la familiarità con quelli connessi al web. Virus (42%), malware (39%) e phishing (39%) sono i più conosciuti. Ma solo il 33% del campione conosce le nuove frodi con l’AI, anche se il 40% sa che l’AI può dare una mano alla prevenzione delle frodi digitali. “Il ruolo dei backup è sempre stato in linea di principio semplice: se qualcosa non funziona correttamente, ripristinare i dati e andare avanti. Ma quando l’attacco diventa visibile, le organizzazioni potrebbero scoprire che anche i backup sono stati compromessi, lasciandole incerte su quali dati possano essere realmente considerati affidabili o, addirittura, impossibilitate ad accedere ai backup”, avverte Vincenzo Granato, Country Manager di Commvault Italia. In questo panorama, “l’affidabilità del backup non è più solo uno strumento di recupero, ma la base per la resilienza operativa“, avverte Vincenzo Granato. Tra il 28 febbraio e il 27 marzo 2026, CERT-AgID conferma che uno tsunami di truffe che sfruttano il brand PagoPA, l’Inps e l’Agenzia delle Entrate, hanno colpito l’Italia. “Proprio questa evoluzione rende evidente un punto fondamentale: il dato non è più soltanto un asset tecnico, ma parte integrante della nostra identità digitale”, spiega Francesco Iezzi: “Ecco perché oggi il backup non serve solo a ripristinare un sistema o a recuperare un file: significa difendere continuità, memoria e integrità di ciò che siamo nel mondo digitale. In un’epoca in cui la tecnologia corre veloce, proteggere i dati significa, in definitiva, proteggere noi stessi”. Secondo la ricerca di Europ Assistance Italia, cala la conoscenza delle soluzioni per proteggere l’identità personale (54%, -8% vs 2024), ma sale il numero di chi ricorre a misure preventive (12%, +10 punti percentuali rispetto al 2024). Il 90% delle Pmi ha impiegto almeno una volta l’AI e il 33% la usa ogni giorno, ma il 40% si preoccupa per l’inaccuratezza delle informazioni e il 38% per l’assenza di controllo umano. Il 55% sa quali sono le potenzialità dell’AI per la prevenzione delle truffe. Dall’indagine di Europ Assistance Italia emerge che l’autenticazione a più fattori (60%), antivirus/anti-malware (56%) e sistemi di gestione delle password (56%) sono i metodi considerati più efficaci per mitigare i rischi in ambito consumer. I rischi più noti presso le Pmi sono virus (52%), malware (52%), phishing (49%) e furto d’identità (46%). Inoltre, tre imprese su 4 sono a conoscenza di soluzioni per tutelare l’identità online: il possesso di antivirus/malware nei dispositivi aziendali è elevato sui PC (85%), ma ancora limitato su smartphone (65%) e tablet (69%). Infatti, il 41% ritiene che la propria azienda sia esposta ai cyber rischi: il primo timore è il furto d’identità (51%). Sfiora la metà degli small business (49%) la quota di Pmi che conosce e si avvale di anti-ransomware. Ritengono metodi di protezione più efficaci gli antivirus e anti-malware (59%), autenticazione a più fattori (57%) e sistemi di gestione delle password (53%). Ma quasi un’azienda su 4 è stata vittima di un attacco nell’arco dell’ultimo semestre e il 35% conosce qualcuno che ne ha subito uno. Dal report di Sophos, State of Ransomware 2025, i backup rappresentano oggi il principale strumento per le organizzazioni per il recupero dei dati cifrati. Il 54% delle realtà colpite li utilizza, ma è il dato più basso negli ultimi sei anni, in continuità con una tendenza in declino. Parallelamente, cresce il peso del pagamento del riscatto: il 49% delle organizzazioni ha scelto questa strada per riottenere l’accesso ai dati. Il divario tra chi si affida ai backup e chi paga gli attaccanti non è mai stato così ridotto. Nel complesso, dal report emerge che il 97% delle organizzazioni che ha subito la cifratura dei dati è stato comunque in grado di recuperarli. Intanto, il costo medio di recupero – escluso il pagamento del riscatto – è calatp da 2,73 milioni a 1,53 milioni di dollari. Ciò indica una maggiore maturità sul fronte della resilienza. Altro elemento rilevante riguarda l’evoluzione delle tecniche d’attacco: oggi appena il 50% degli attacchi ransomware porta alla cifratura dei dati, a conferma del crescente ricorso a modelli basati su esfiltrazione delle informazioni ed estorsione. “I backup restano una delle misure di protezione più importanti che le organizzazioni possono adottare contro il ransomware e continuano a essere il metodo più utilizzato per ripristinare i dati cifrati. Allo stesso tempo, stiamo osservando alcuni segnali incoraggianti”, conferma Marcel Bornhöfft, Field CISO Associate di Sophos. Sono sette le linee guida per mettere in campo un’efficace strategia di backup: la strategia 3-2-1-0: alla regola 3-2-1 si aggiunge un nuovo strato extra di sicurezza (che consiste nel mantenere 3 copie dei dati, archiviate su 2 tipi di supporti differenti, con 1 copia fuori sede per garantire la continuità delle operazioni aziendali); analisi compiuta di RTO (recovery time objective) e RPO (recovery point objective): occorre un equilibrio per stabilire quali sistemi e tipi di dati meritano investimenti maggiori per ridurre al minimo e rendere brevi RTO e RPO; ottimizzare lo spazio di archiviazione, avvalendosi di deduplicazione globale integrata; crittografia dei dati per rendere sicuri i backup, oggi vulnerabili ai cyber attacchi; semplificare supporto e manutenzione con una dashboard centralizzata; automatizzazione del processo di backup; sottoporre a test costanti la strategia di backup e recovery. “I dati rappresentano uno degli asset più preziosi e vulnerabili per tutte le organizzazioni, indipendentemente dal settore, e backup frequenti ed efficaci contribuiscono a ridurre i tempi di inattività, preservare la continuità operativa, supportare gli obblighi di conformità e accelerare il ripristino dopo eventi critici”, sottolinea Corey Nachreiner. “Il messaggio più importante per la Giornata Mondiale del Backup di quest’anno è semplice: la preparazione conta solo quando il ripristino è stato dimostrato. Non basta eseguire il backup dei dati. È essenziale testare, proteggere e dimostrare la capacità di recupero. Le organizzazioni che si riprendono più velocemente dagli attacchi sono quelle che sanno già che i loro dati sono integri, facilmente accessibili e ripristinabili”, prosegue Corey Nachreiner. “Oggi tutti parlano di ‘fare backup‘, ma il backup perfetto non è quello che esiste: è quello che si ripristina”, conferma Sandro Sana: “Se non testi il restore, stai solo accumulando copie e speranze. La differenza tra resilienza e disastro si misura nel giorno in cui devi usarlo”. Altre tre regole possono accompagnare le sette le linee guida per backup efficaci: Entra ID: per conservare i dati soltanto per 30 giorni, mentre alcune informazioni, come i gruppi di sicurezza, non sono conservate; ripristino con cautela: se il ripristino avviene senza scansionare i malware, si potrebbe correre il rischio di introdurre inavvertitamente minacce nella rete; effettuare test sul backup. In occasione del World Backup Day 2026, secondo Sean Deuby, “le organizzazioni sono chiamate ad adottare un approccio più integrato, che consideri esplicitamente la compromissione dei sistemi di identità (come Active Directory, Entra ID, Okta o Ping Identity) all’interno delle strategie di recovery. Un passaggio cruciale per rafforzare la resilienza, ridurre le interruzioni operative e garantire un recupero più efficace in caso di attacco”. “Una strategia di backup solida è alla base di qualsiasi azienda moderna e deve includere un piano di ripristino chiaro, per garantire che i team sappiano quali sistemi critici devono essere ripristinati per primi quando ogni minuto è fondamentale. Altrettanto importante quanto la frequenza e la strategia è la qualità dei backup. È indispensabile monitorarne lo stato ed eseguire test periodici di ripristino, poiché il vero valore di un backup risiede nella sua velocità e affidabilità di recupero sotto pressione. La Giornata Mondiale del Backup dovrebbe rappresentare non solo un momento per confermare l’esistenza dei backup, ma anche per verificarne l’effettiva efficacia“, avverte Corey Nachreiner. Le aziende adottano tecnologie come l’intelligenza artificiale, dove le decisioni e le operazioni dipendono da ingenti volumi di dati in continua crescita. “Se le informazioni sottostanti sono corrotte o ‘avvelenate’, le conseguenze possono diffondersi rapidamente attraverso sistemi e rendendo gli output inutilizzabili o inaffidabili”, spiega Vincenzo Granato. Ecco perché il il World Backup Day 2026 non dovrebbe essere solo “un promemoria per mantenere copie dei dati, ma per garantire che tali copie siano pulite, validate e pronte per il ripristino”. Il semplice data recovery senza la verificar dell’integrità rischia infatti di reintrodurre le stesse minacce che hanno provocato l’incidente. “Le aziende devono sempre più pensare in termini di recovery pulito – la capacità di identificare dati affidabili, isolare ambienti compromessi e ripristinare i sistemi in modo tale da prevenire la reinfezione. Devono anche essere regolarmente testati per assicurarsi che siano backup validi e privi di errori”, conclude Vincenzo Granato. cleanroom Le cleanroom basate su cloud forniscono per esempio un ambiente sicuro attivabile e disattivbile, in base alle esigenze di test e ripristino, a un costo minimo. Dobbiamo andare oltre il tradizionale data recovery, guardando anche alla ricostruzione delle applicazioni cloud, spesso l’attività più costosa in termini di tempo quando si esegue il ripristino da un attacco. In pochi minuti, l’automazione permette alle aziende di garantirsi di mantenere la business continuity anche durante una situazione di crisi. onformità normativa, cifratura e replica Secondo il Cloud Storage Index 2026 di Wasabi Technologies, a livello mondiale, appena il 47% delle organizzazioni afferma di confidare nella propria capacità di mantenere i dati nel cloud pubblico operativi e inalterati in seguito a un cyber attacco. In Italia la quota cala al 39%. Inoltre, il 44% delle aziende globale (ma l’Italia il 41%) dichiara di aver subito, nell’ultimo anno, un attacco informatico con perdita di accesso ai dati nel cloud pubblico. Stando al report, il 53% delle organizzazioni internazionali sfrutta oggi l’IA in modo specifico per monitorare e rilevare le anomalie. Ma si cala al 44% in Italia. Inoltre il 91% delle aziende (il 92% in Italia) protegge gli asset legati all’IA grazie a backup dei dati e delle applicazioni AI in produzione. Il 68% delle imprese globali (il 72% in Italia) effettua il backup degli ambienti AI di test e sviluppo. “È fondamentale comprendere che i backup garantiscono la disponibilità dei dati, ma non ne assicurano la riservatezza. La crittografia rappresenta una prima linea di difesa essenziale contro accessi non autorizzati e violazioni, e i dati di backup non fanno eccezione. Con il ransomware che combina sempre più spesso interruzione operativa, furto di dati ed estorsione, le organizzazioni devono proteggere endpoint, identità e dati sensibili, per impedire agli attaccanti di esporre o monetizzare facilmente le informazioni sottratte“, conclude Corey Nachreiner. Encryption e replication (32%) rimangono le funzionalità di sicurezza del cloud pubblico più gettonate. In Italia, però, le aziende stanno investendo maggiormente in capacità più evolute come il rilevamento dei dati personali identificabili (PII) e la conformità normativa (Nis2, Dora, Gdpr, Cyber resilience act eccetera), entrambe al 40%, seguite da replication al 36% ed encryption al 31%. Il 63% delle organizzazioni a livello globale (il 65% in Italia) usa l’immutabilità, spostandosi verso funzionalità di sicurezza dei dati più evolute, necessarie per la protezione di dataset sempre più critici nel cloud. Con l’accesso al cloud che subisce interruzioni da parte di cyber attacchi e con i workload AI che fanno esplodere i volumi di dati, il gap tra investimenti aziendali e fiducia nella resilienza resta un rischio significativo. Di conseguenza, le aziende sono spinte a superare la difesa perimetrale adottando un approccio alla resilienza e alla protezione dell’integrità dei processi di ripristino. “La riduzione dei costi complessivi di recupero potrebbe indicare che le organizzazioni stanno migliorando la propria resilienza, anche nel modo in cui gestiscono e utilizzano i backup. Tuttavia, il ridursi del divario tra le organizzazioni che utilizzano i backup e quelle che pagano un riscatto mette in evidenza una sfida importante. Potrebbe indicare che alcune organizzazioni non sono ancora in grado di fare pieno affidamento sui propri backup nel momento in cui serve davvero, ma riflette anche il modo in cui gli attaccanti stanno spostando le proprie tattiche verso il furto di dati e l’estorsione, contesti in cui il solo recupero non basta”, avverte Marcel Bornhöfft, in occasione del World Backup Day 2026. Il World Backup Day 2026 ci ricorda che “i backup non sono importanti solo perché conservano i dati, ma perché rendono possibile il recupero. Senza la capacità di ripristinare efficacemente i sistemi, anche il backup più completo perde di valore. In un contesto in cui le minacce informatiche continuano a evolversi – anche grazie all’uso crescente dell’intelligenza artificiale – le organizzazioni devono essere in grado di predisporre ambienti di ripristino “puliti” e riportare rapidamente online i sistemi critici, in modo sicuro e al di fuori del controllo degli attaccanti. Questo implica un’estensione delle strategie di recovery che includa l’intera infrastruttura su cui si basa il funzionamento aziendale, con particolare attenzione ai sistemi di identità, elementi chiave per accesso, controllo e fiducia. Dare per scontato che gli attaccanti lascino indenni questi sistemi è un errore sempre più rischioso”, mette in guardia Sean Deuby. “La ricorrenza del World Backup Day 2026 offre anche l’occasione per ribadire che la pianificazione del ripristino non dovrebbe limitarsi a ciò che può essere recuperato, ma deve concentrarsi su quanto efficacemente un’organizzazione è in grado di reagire quando i sistemi critici non sono disponibili. In questo scenario, il ripristino delle identità sta assumendo un ruolo centrale nella gestione delle crisi. A differenza di altri ambienti, infatti, riportare operativi i sistemi di identità non equivale automaticamente a potersi fidare della loro integrità dopo una compromissione. Quando l’identità viene meno o non è verificabile, le conseguenze si estendono oltre il piano tecnico, influenzando anche comunicazione, coordinamento e capacità decisionale”, evidenzia Sean Deuby. rischi dell’ecosistema digitale “L’essere umano nasce con la paura del vuoto – ci spiega Domenico Raguseo – Non ha bisogno di una giornata che ci ricordi che buttarsi da un ponte o da un piano alto può avere conseguenze fatali, non ha bisogno di corsi sulla consapevolezza che ci dicono che non ci si deve buttare senza paracadute da un aereo e se lo facciamo, lo facciamo essendo consci dei rischi . Sappiamo anche che con un paracadute i rischi si riducono, ma non si azzerano. Questo è la conseguenza di milioni di anni di evoluzione che ha salvaguardato le specie umane che avevano comportamenti più prudenti , per cui un bambino anche gattonando tende a tenersi a dovuta distanza da immagini che rapprendano il vuoto”. In questo scenario, in cui le infrastrutture AI sono in rapida crescita, crescono gli incidenti cyber che hanno nel mirino i dati nel cloud. “La specie umana invece non ha avuto tempo per comprendere i rischi che sono associati all’ecosistema digitale“, mette in guardia Domenico Raguseo: “Dipendiamo dai dati in maniera irreversibile, ma non riflettiamo su cosa potrebbe accadere se questi dati scomparissero e tantomeno ad investire nella protezione e resilienza di questi dati (dalla semplice password ai documenti, dalle foto ai video, le email eccetera)”. “Non è dunque sufficiente parlare di ‘gioielli della corona’ per risolvere il problema. Dedicare del tempo per ricordarci di quanto i dati siano importanti e come vanno protetti, investire in consapevolezza è sempre opportuno, non possiamo attendere che l’evoluzione faccia il suo naturale corso nella selezione delle specie virtuose“, conclude Raguseo. “Tra ransomware, errori di configurazione, e guasti, perdere informazioni è più facile di quanto si pensi. Fare backup non basta: serve una strategia solida, con copie offline o immutabili e test periodici di ripristino. Il backup è parte di un più ampio processo atto a garantire la continuità operativa, e non solo una precauzione tecnica. Investire oggi in resilienza significa evitare danni domani, sia per le aziende che per i singoli utenti“, sottolinea Paganini. E in attesa dei frutti evolutivi, impariamo a fare backup, disaster recovery e a garantire la continuità del business.
cybersecurity360.itMar 31, 2026extracted
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad actors for malvertising and distributing malware. "TikTok has been historically abused to distribute malicious links and social engineering instructions," Push Security said. "This includes multiple infostealers like Vidar, StealC, and Aura Stealer delivered via ClickFix-style instructions with AI-generated videos posed as activation guides for Windows, Spotify, and CapCut." The campaign begins with tricking victims into clicking on a malicious link that directs them to either a lookalike page impersonating TikTok for Business or a page that's designed to impersonate Google Careers, along with an option to schedule a call to discuss the opportunity. It's worth noting that a prior iteration of this credential phishing campaign was flagged by Sublime Security in October 2025, with emails masquerading as outreach messages used as a social engineering tactic. Regardless of the type of page served, the end goal is the same: perform a Cloudflare Turnstile check to block bots and automated scanners from analyzing the contents of the page and serve a malicious AitM phishing page login page that's designed to steal their credentials. The phishing pages are hosted on the following domains - welcome.careerscrews[.]com welcome.careerstaffer[.]com welcome.careersworkflow[.]com welcome.careerstransform[.]com welcome.careersupskill[.]com welcome.careerssuccess[.]com welcome.careersstaffgrid[.]com welcome.careersprogress[.]com welcome.careersgrower[.]com welcome.careersengage[.]com welcome.careerscrews[.]com The development comes as another phishing campaign has been observed using Scalable Vector Graphics (SVG) file attachments to deliver malware to targets located in Venezuela. According to a report published by WatchGuard, the messages have SVG files with file names in Spanish, masquerading as invoices, receipts, or budgets. "When these malicious SVGs are opened, they communicate with a URL that downloads the malicious artifact," the company said. "This campaign uses ja.cat to shorten URLs from legitimate domains that have a vulnerability that allows redirects to any URL, so they point to the original domain where the malware is downloaded." The downloaded artifact is a malware written in Go that shares overlaps with a BianLian ransomware sample detailed by SecurityScorecard in January 2024. "This campaign is a strong reminder that even seemingly harmless file types like SVGs can be used to deliver serious threats," WatchGuard said. "In this case, malicious SVG attachments were used to initiate a phishing chain that led to malware delivery associated with BianLian activity."
thehackernews.comMar 27, 2026extracted
Fake enterprise VPN sites used to steal company credentials
A threat actor tracked as Storm-2561 is distributing fake enterprise VPN clients from Ivanti, Cisco, and Fortinet to steal VPN credentials from unsuspecting users. The attackers manipulate search results (SEO poisoning) for common queries like “Pulse VPN download” or “Pulse Secure client” to redirect victims to spoofed VPN vendor sites that closely mimic VPN solutions from legitimate software vendors. After examining the attack and command-and-control (C2) infrastructure, Microsoft researchers discovered that the same campaign used domains related to Sophos, Sonicwall, Ivanti, Check Point, Cisco, WatchGuard, and others, targeting users of multiple enterprise VPN products. In the observed attack, Microsoft found that the fake sites link to a GitHub repository (now taken down) that hosts a ZIP archive containing a fake VPN MSI installer. When executed, this file installs ‘Pulse.exe’ into %CommonFiles%\Pulse Secure, and drops a loader (dwmapi.dll) and a variant of the Hyrax infostealer (inspector.dll). The fake VPN client displays a legitimate-looking login interface that invites victims to enter their credentials, which are captured and exfiltrated to the attacker's infrastructure. The malware, which is digitally signed with a legitimate, but now revoked, certificate from Taiyuan Lihua Near Information Technology Co., Ltd., also steals VPN configuration data stored in the ‘connectionsstore.dat’ file from the legitimate program’s directory. To reduce suspicion, the fake VPN client displays an installation error after stealing the credentials, and redirects them to the real vendor’s site to download the legitimate VPN client. “If users successfully install and use legitimate VPN software afterward, and the VPN connection works as expected, there are no indications of compromise to the end users […], [who] are likely to attribute the initial installation failure to technical issues, not malware,” explains Microsoft. Meanwhile, in the background, the infostealer malware creates persistence for Pulse.exe via the Windows RunOnce registry key, ensuring the infection survives system reboots. The researchers recommend that system administrators enable cloud-delivered protection in Defender, run EDR in block mode, enforce multi-factor authentication, and use SmartScreen-enabled browsers. Microsoft has also provided indicators of compromise (IoCs) and hunting guidance to help detect and block this campaign early. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 13, 2026extracted
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below - CVE-2019-17571 (CVSS score: 9.8) - A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) - An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration "The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571," SAP security company Onapsis said. "It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application." CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content. "Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10," Onapsis added. The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws. On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution. Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface. "A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls," HPE said. "In some cases, this could enable resetting the admin password." "Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected," Ross Filipek, CISO at Corsica Technologies, said in a statement. "A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today's hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk." Software Patches from Other Vendors Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD Arm Atlassian Bosch Broadcom (including VMware) Canon Cisco Commvault Dassault Systèmes Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Google Wear OS Grafana Hitachi Energy Honeywell HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird n8n NVIDIA Palo Alto Networks QNAP Qualcomm Ricoh Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Synology TP-Link Trend Micro WatchGuard Western Digital Zoom, and Zyxel
thehackernews.comMar 11, 2026extracted
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
It's Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services. Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Windows components that could be abused to bypass security features, escalate privileges, and trigger a denial-of-service (DoS) condition. Elsewhere, Adobe released updates for Audition, After Effects, InDesign Desktop, Substance 3D, Bridge, Lightroom Classic, and DNG SDK. The company said it's not aware of in-the-wild exploitation of any of the shortcomings. SAP shipped fixes for two critical-severity vulnerabilities, including a code injection bug in SAP CRM and SAP S/4HANA (CVE-2026-0488, CVSS score: 9.9) that an authenticated attacker could use to run an arbitrary SQL statement and lead to a full database compromise. The second critical vulnerability is a case of a missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform (CVE-2026-0509, CVSS score: 9.6) that could permit an authenticated, low-privileged user to perform certain background Remote Function Calls without the required S_RFC authorization. "To patch the vulnerability, customers must implement a kernel update and set a profile parameter," Onapsis said. "Adjustments in user roles and UCON settings might be required to not interrupt business processes." Rounding off the list, Intel and Google said they teamed up to examine the security of Intel Trust Domain Extensions (TDX) 1.5, uncovering five vulnerabilities in the module (CVE-2025-32007, CVE-2025-27940, CVE-2025-30513, CVE-2025-27572, and CVE-2025-32467), and nearly three dozen weaknesses, bugs, and improvement suggestions. "Intel TDX 1.5 introduces new features and functionality that bring confidential computing significantly closer to feature parity with traditional virtualization solutions," Google said. "At the same time, these features have increased the complexity of a highly privileged software component in the TCB [Trusted Computing Base]." Software Patches from Other Vendors Security updates have also been released by other vendors in recent weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD AMI Apple ASUS AutomationDirect AVEVA Broadcom (including VMware) Canon Check Point Cisco Citrix Commvault ConnectWise D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal F5 Fortinet Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Thunderbird n8n NVIDIA Phoenix Contact QNAP Qualcomm Ricoh Rockwell Automation Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Spring Framework Supermicro Synology TP-Link WatchGuard Zoho ManageEngine Zoom, and Zyxel
thehackernews.comFeb 11, 2026extracted
Data protection day: nell’era dell’AI agentica serve una disciplina di resilienza
Il 28 gennaio si celebra il Data Protection Day 2026, la giornata internazionale dedicata alla protezione dei dati che nel mondo prende il nome di Data Privacy Day e sta acquisendo nuova centralità mentre la protezione dei dati è sotto pressione a causa dei rischi legati all’Agentic AI e all’AI generativa. “Con il passaggio dall’analisi a un processo decisionale autonomo, il concetto di privacy non riguarda più solo le modalità di raccolta o archiviazione dei dati, ma anche la responsabilità”, avverte Paolo Lossa, Country Sales Director di CyberArk Italy. Secondo Corey Nachreiner, Chief Security Officer di WatchGuard, “oggi il rischio per la privacy dei dati non deriva principalmente da attaccanti che superano un firewall, ma dalla compromissione delle identità e dall’uso improprio di accessi considerati affidabili”. “La Giornata della protezione dei dati personali ci ricorda che privacy e cyber security sono destinate a vincere o fallire insieme, e che queste strategie devono essere sempre allineate”, sottolinea Drew Bagley, VP and Counsel, Privacy and Cyber Policy di CrowdStrike. “Questa ricorrenza rischia ogni anno di diventare simbolica, ricca di buone intenzioni, ma povera di cambiamenti reali”, commenta Pierluigi Paganini, analista di cyber security e Ceo Cybhorus. Ecco come “evitare l’ennesimo esercizio retorico”, perché dalla tutela dei dati personali dipende la difesa della democrazia, la salvaguardia della libertà e della dignità delle persone. Indice degli argomenti Data Protection Day 2026: la protezione dei dati è questione di resilienza Nel Data Privacy Day vale la pena ricordare che “la protezione dei dati non è un esercizio ‘una tantum’, ma una disciplina di resilienza”, sottolinea Bruno Filippelli, Sales Director di Semperis in Italia: “Per le aziende significa sapere dove risiedono i dati, limitarne la diffusione, controllare gli accessi e rendere verificabili decisioni e responsabilità. Il ransomware lo dimostra ogni giorno: la privacy si regge su governance e continuità operativa, con processi, persone e controlli che funzionano sotto stress, quando servono ripristino rapido e responsabilità chiare”. I dati, la conservazione dei dati raccolti dovrebbe seguire le normative vigenti in materia, ma a volte avviene per periodi indefiniti e sono impiegati per profilare individui in maniera dettagliata, spaziando dalle preferenze comportamentali alle abitudini di consumo, dallo stato di salute a quello socioeconomico. Questo rischio si è alzato con la diffusione dell’AI agentica. “Nel 2026, l’uso diffuso di agenti autonomi ha trasformato la governance dell’Intelligenza Artificiale da priorità strategica a imperativo per la sopravvivenza delle aziende. L’AI accelera la portata degli attacchi e trasforma la ‘fiducia’ in una vulnerabilità. È evidente come le conseguenze delle compromissioni ai sistemi di AI siano maggiori rispetto a quelle di un attacco ransomware, minando in modo permanente la fiducia dei clienti e delle autorità di regolamentazione. AI Act non è un ostacolo, ma un investimento Per mitigare questo rischio, le organizzazioni devono andare oltre la semplice prevenzione e adottare una mentalità basata sulla resilienza e sul presupposto della violazione. È necessaria una solida governance dei dati, che garantisca visibilità – dalla formazione alla comprensione – e che consideri la conformità alle normative come l’AI Act non un ostacolo, ma un investimento strategico per un’architettura di fiducia duratura”, spiega Alessio Stellati, Regional Vice President Italy, Spain & Portugal di Rubrik. Da quando l’integrazione dell’intelligenza artificiale in tutti gli ambienti aziendali è sempre profonda, “guidando i flussi di lavoro e un costante movimento di dati, tendiamo quasi a dare per scontato il nuovo paradigma di accesso e condivisione delle informazioni. Tuttavia, una protezione reale dipende dalla disponibilità di una visibilità, una privacy by design e una resilienza che operino in tempo reale“, avverte Drew Bagley. “Le organizzazioni stanno implementando l’AI in ambienti ad alto impatto più rapidamente di quanto possano essere aggiornati i quadri di governance, sollevando questioni spinose in materia di responsabilità, qualità dei dati e supervisione quando i sistemi basati sull’AI producono conseguenze indesiderate. Esiste un crescente divario di responsabilità poiché le decisioni basate sull’AI influenzano sempre più le persone, i risultati e la fiducia”, mette in guardia Paolo Lossa. Per le organizzazioni, la priorità deve essere quella di proteggere l’AI nel punto in cui il rischio per la privacy è più elevato ovvero l’agente AI stesso. “Questi agenti operano con una velocità, una portata e una capacità di accesso che spesso superano quelli degli utenti umani, rendendoli una nuova classe di identità altamente privilegiate. Trattare gli agenti AI come ‘software affidabili’ piuttosto che come identità privilegiate può rivelarsi molto rischiosi. In un mondo ibrido di collaborazione tra uomo e macchina, la sicurezza dell’AI agentica diventa un controllo fondamentale della privacy, che richiede la possibilità di concedere privilegi minimi di accesso, un monitoraggio continuo e una chiara responsabilità umana. Con una regolamentazione ancora in evoluzione, le organizzazioni devono assumere un ruolo guida nella protezione della privacy nell’era dell’AI”, evidenzia Paolo Lossa. Stiamo osservando come i criminali informatici facciano sempre più leva sul social engineering e su tecniche di inganno potenziate dall’intelligenza artificiale per rubare credenziali, impersonare utenti legittimi ed esfiltrare dati in modo silenzioso. “In molti casi, questi attacchi hanno origine da qualcosa di apparentemente banale, come un link o un download ingannevole, a dimostrazione di quanto la consapevolezza degli utenti sia fondamentale tanto quanto le misure di sicurezza tecniche”, ricorda Corey Nachreiner, Chief Security Officer di WatchGuard. “Questo cambiamento spiega perché oggi la protezione dei dati richieda un approccio più semplice e unificato, che integri identità, endpoint e controlli di sicurezza in modo coerente. Quando questi livelli operano in silos, si creano inevitabilmente delle falle che gli attaccanti sono pronti a sfruttare. Accorgimenti di base come verificare l’origine dei download, utilizzare l’autenticazione a più fattori e mantenere una corretta igiene delle credenziali possono fermare gli attacchi anche quando le credenziali sono prese di mira. Grazie a queste pratiche, le organizzazioni possono intercettare le minacce molto prima, evitando che il furto di credenziali si trasformi in una violazione dei dati, in sanzioni normative o in danni reputazionali di lungo periodo”, spiega Corey Nachreiner. Nell’era del cloud e dell’AI, uno dei principali accorgimenti per ridurre il rischio di data leakage è l’adozione di una governance rigorosa. “È infatti fondamentale”, secondo Alessio Agnello, SE Manager Italy, Greece, Malta & Israel di Netskope, “consentire esclusivamente l’utilizzo di piattaforme GenAI di livello Enterprise, inibendo tecnicamente l’accesso tramite account personali al fine di eliminare il fenomeno della Shadow AI. In parallelo, è necessario implementare sistemi di Data Loss Prevention (DLP) attivi, capaci di bloccare l’inserimento di proprietà intellettuale o dati personali (PII) nei prompt e di impedire il caricamento di file su servizi di cloud storage privati. Solo attraverso una netta segregazione tra ambiente aziendale e personale è possibile mitigare efficacemente le minacce interne e le sempre più frequenti violazioni delle policy”. Infatti “l’identità è un punto critico della privacy”, conferma Mark Molyneux, Field CTO Northern Europe di Commvault: “Negli ambienti cloud, le identità compromesse sono spesso la via più rapida per raggiungere i dati sensibili. Resilienza significa rilevare precocemente gli accessi anomali, limitare il raggio d’azione dell’attacco e ripristinare con sicurezza quando i controlli di identità vengono aggirati. Questo è il motivo per cui un ripristino pulito è fondamentale. In caso di ransomware o compromissione basata su identità, il rischio è ripristinare risorse errate al momento sbagliato, senza averne validato l’integrità. Le aziende mature danno priorità a isolamento, analisi forense e verifica, nonché alla ripetibilità, in modo da poter ripristinare i servizi critici, riducendo il rischio di nuova infezione o esposizione o dati corrotti”. Il Data Protection Day 2026 rappresenta “un utile rimando alla tensione che le aziende stanno vivendo in tema di intelligenza artificiale. Da un lato, GenAI e agentic AI stanno offrendo reali vantaggi in termini di produttività, dall’altro, stanno creando nuovi modi in cui i dati sensibili possono venire esposti – specialmente con la continua integrazione nelle attività quotidiane di strumenti di AI e agenti autonomi”, mette in guardia Matt Cooke, Director, Cybersecurity Strategy EMEA di Proofpoint. “Una volta che informazioni confidenziali o dati personali vengono condivisi con un sistema di AI, può essere difficile capire dove vadano a finire o come vengano riutilizzati: è questo che preoccupa molti responsabili della sicurezza”, continua Matt Cooke: “La realtà è che la perdita di dati non avviene da sola. Inizia dalle persone e, ora, anche dagli agenti AI che agiscono per loro conto. Questo si riflette in quello che ci stanno confermando i CISO: il 77% delle aziende italiane ha subìto una perdita materiale di dati sensibili nell’ultimo anno, e l’errore umano rimane il fattore determinante“. “Poiché lo spazio di lavoro agentico sta diventando una realtà, i team di sicurezza devono adottare un approccio alla protezione dei dati che sia focalizzato sulla persona, applicata in modo coerente su email, cloud, endpoint, web e strumenti di AI, fornendo agli utenti strumenti adeguati e formazione costante. Solo così le aziende potranno godere dei vantaggi dell’AI senza mettere a rischio la confidenzialità dei dati”, conclude Matt Cooke. Oggi “la nostra valuta sono i dati. Le informazioni personali vengono acquistate, vendute ed esposte tramite offerte in tempo reale (RTB) più e più volte, anche nello stesso giorno”, spiega Anthony Cusimano, Director of Solutions Object First. Deepfake, campagne di phishing, data poisoning, agenti di intelligenza artificiale dimostrano come l’IA abbia favorito il loro sfruttamento: “I nostri dati oggi sono più esposti a minacce che in qualunque altro momento della storia a causa degli exploit e degli attacchi informatici basati sull’intelligenza artificiale. Ecco perché è così importante disporre di controlli adeguati che proteggano i propri dati”, avvisa Anthony Cusimano. Nel 2026, secondo Mark Molyneux, “la domanda che ogni consiglio di amministrazione dovrebbe porsi è se possiamo dimostrare il controllo sui dati personali e mantenere la fiducia anche in caso di interruzioni, indipendentemente dal fatto che siano dovute a un’intrusione, una configurazione errata, un errore interno o un incidente di un fornitore”. “Le aziende non devono più dichiarare intenzioni, ma fornire prove concrete. Questo approccio ‘basato sull’evidenza’ si riflette chiaramente anche in Europa ed è richiesto, tra le altre cose, dai requisiti normativi di GDPR, NIS2 e DORA, che impongono alle aziende di dimostrare misure tecniche e organizzative appropriate per l’accesso ai dati e la gestione del rischio, e di fornire una protezione speciale per i loro sistemi critici, come i servizi di directory”, avverte Mark Molyneux. “È essenziale registrare chi è autorizzato ad accedere ai sistemi critici e quali ruoli e permessi esistono. Entrambi i set di regole richiedono esplicitamente che gli account di admin e di servizio siano protetti separatamente e che le loro azioni siano registrate in modo distinto. In parole semplici, la preparazione in materia di privacy per questi set di dati dipende dalla capacità operativa: contenimento, validazione e ripristino sicuro, non solo dalle policy“, sottolinea Mark Molyneux. onvergenza fra privacy e resilienza Secondo Mark Molyneux, “è qui che convergono privacy e resilienza. Quando sono coinvolti dati personali, gli incidenti diventano eventi che minano la fiducia. Le aziende sono giudicate in base alla loro capacità di rispondere in modo decisivo e ripristinare le operazioni con sicurezza”. Un approccio pratico consiste nel “definire le priorità critiche per la fiducia: dati, sistemi e processi che devono essere protetti e ripristinati per primi, sotto pressione. Piani e obiettivi da soli non sono sufficienti. Il fattore differenziante è la capacità di recovery comprovata, con chiari diritti decisionali e workflow collaudati che consentono un ripristino pulito e rapido”, aggiunge Mark Molyneux. Con l’ascesa degli LLM e degli agenti AI, le aziende si trovano sempre più spesso nella condizione di dover utilizzare dati sensibili per addestrare e testare i propri modelli. “Tuttavia, anche quando i processi di training considerano tutti gli accorgimenti necessari per rispettare la riservatezza, i dati sensibili possono facilmente finire nei corpora di addestramento, nei set di valutazione o nelle librerie di prompt. E ciò accade soprattutto quando le aziende sono chiamate a creare e sviluppare casi d’uso dell’AI in velocità”, esprime i suoi timori Sergio Gago, CTO di Cloudera. “I dati sintetici rappresentano in questo senso una soluzione pratica: generati da algoritmi, sono progettati per rispecchiare i set di dati del mondo reale senza riprodurre i record effettivi. Se utilizzati correttamente, consentono la messa a punto dei modelli di AI, la valutazione della loro efficacia su larga scala e il raffinamento dei dati per gli agenti, riducendo al contempo i rischi per la privacy”. disciplina ingegneristica per trattare i dati sintetici Tuttavia, questi dati non sono una soluzione miracolosa. Infatti, “e generati in modo inadeguato – per esempio conservando combinazioni di caratteristiche rare, o se riflettono troppo fedelmente esempi del mondo reale – possono comunque divulgare informazioni sensibili”, avverte Sergio Gago. “Per essere veramente efficaci, i dati sintetici devono essere trattati come una disciplina ingegneristica, non come ultima risorsa, sviluppando e applicando protocolli e metodologie accurate. Le organizzazioni devono prima definire lo scopo per cui hanno bisogno di questi dati e poi determinare come devono essere generati. In ogni caso, i dati sintetici non possono sostituire universalmente i dati reali e non eliminano la necessità di una governance”, suggerisce Sergio Gago. In occasione del Data Protection Day 2026, Sergio Gago invita le aziende a “considerare i dati sintetici come una leva per un’innovazione sicura, a condizione che siano generati, supervisionati e integrati in modo adeguato in una governance solida per proteggere la riservatezza durante tutto il ciclo di vita dell’AI”, Genetec raccomanda strategie per la tutela delle informazioni sensibili senza compromettere l’efficacia dei processi operativi. Strategie trasparenti, tecnologie resilienti e partnership basate sulla fiducia, tutti elementi cruciali per mantenere l’equilibrio fra la protezione e la sicurezza fisica, in uno scenario normativo e di rischio in continua evoluzione. In questo contesto, Genetec suggerisce alcune linee guida per rafforzare la tutela dei dati nei sistemi di sicurezza fisica: le aziende devono delineare una strategia chiara per la tutela dei dati; adottare sistemi basati sul principio di “Privacy by Design”; implentare efficaci difese informatiche nel tempo; usare servizi cloud per favorire resilienza e conformità; selezionare partner che abbiano a cuore il rispetto della privacy e della trasparenza. “I dati relativi alla sicurezza fisica possono essere estremamente sensibili: per questo la loro tutela richiede molto più di misure di tutela basilari o rassicurazioni generiche”, afferma Mathieu Chevalier, Principal Security Architect di Genetec. “Alcune soluzioni presenti sul mercato trattano i dati come una risorsa da sfruttare o condividere per finalità diverse da quelle originali, esponendo le aziende a gravi rischi per quanto riguarda la privacy delle informazioni. Le aziende devono invece poter contare su limiti precisi d’utilizzo, controlli rigorosi lungo tutto il ciclo di vita delle informazioni e tecnologie progettate per garantire la privacy sin dalla fase di progettazione, e non come semplice integrazione a posteriori“, secondo Mathieu Chevalier. In questo Data Protection Day 2026, occorre rivedere le proprie impostazioni sulla privacy, attivare un’autenticazione rafforzata e cooperare con organizzazioni affidabili che mettano in primo piano sicurezza e ripristino dei dati. Occorre inoltre promuovere trasparenza e responsabilità, oltre che adottare misure proattive per proteggere il proprio digital footprint. Secondo Paganini, “la riflessione principale per evitare l’ennesimo esercizio retorico è una sola: la privacy non può restare un tema ‘celebrativo’, deve diventare una pratica quotidiana e misurabile. Parlare di protezione dei dati senza collegarla a scelte concrete, tecnologiche, organizzative e culturali, svuota il messaggio di significato. A mio parere urge un cambiamento culturale in un momento di grandi incertezze e continui cambiamenti, tecnologici e normativi”. Le normative in vigore (Ai Act eccetera) sono importanti, ma non sono sufficienti a fronteggiare l’utilizzo dei dati da parte dell’intelligenza artificiale. passare dai principi ai fatti Storage di backup a prova di ransomware con immutabilità assoluta, approcci Zero Trust, automatizzare l’hardening ed eliminare i controlli amministrativi non necessari sono buone pratiche per garantire la privacy. “Minore è la complessità per gli utenti, maggiore sarà l’affidabilità della protezione dei dati di cui sono responsabili”, secondo Anthony Cusimano. “La sfida sulla privacy è passare dai principi ai fatti“, conclude Paganini: “Progettare servizi con la tutela dei dati come fulcro, investire in sicurezza, formare persone consapevoli e garantire trasparenza reale. In un’era di AI e big data, la privacy non vuole e può bloccare l’innovazione ma deve aiutarci a renderla sostenibile. Il Data Protection Day 2026 conta solo se diventa un momento di verifica concreta su quanto fatto e su cosa migliorare”. Infatti “se la privacy viene vista unicamente come un obbligo normativo, sarà solo una lista di controllo della conformità, se invece la si considera una parte fondamentale della propria strategia di resilienza – un elemento che dimostri di poter resistere a ransomware, minacce interne e uso dei dati da parte dell’intelligenza artificiale – rappresenterà un potente fattore di differenziazione per essere competitivi”, mette in risalto Anthony Cusimano.
cybersecurity360.itJan 28, 2026extracted
Organizations Warned of Exploited Linux Vulnerabilities
The US cybersecurity agency CISA on Monday expanded the Known Exploited Vulnerabilities (KEV) catalog with five flaws, including two Linux bugs. The first Linux issue is CVE-2026-24061 (CVSS score of 9.8), a critical-severity defect in GNU Inetutils that has been exploited within days of its public disclosure last week. It is an authentication bypass in the GNU telnetd service, which does not sanitize the USER environment variable before passing it to the login function. The USER environment variable is used to pre-fill the username used for authentication and, because an attacker can control it via the Telnet protocol, the attacker can supply an ‘-f’ flag to bypass authentication. An attacker can exploit the bug by sending crafted Telnet commands to set the USER variable, bypass authentication, and obtain a root shell, gaining remote code execution (RCE) on vulnerable systems, SafeBreach explains. CVE-2026-24061 was introduced in GNU Inetutils version 1.9.3, which was released in May 2015, and impacts all iterations up to and including version 2.7, which was rolled out in December 2025. Within days of the flaw’s public disclosure on January 20, GreyNoise reported seeing 60 exploitation attempts from 18 unique attack sources. The attacks involved reconnaissance, SSH persistence, and malware deployment. As SafeBreach points out, more than 200,000 systems have a Telnet service exposed to the internet (or over 1 million, per Censys), but only those using the GNU telnetd service are vulnerable. The second Linux issue added to the KEV catalog this week is CVE-2018-14634 (CVSS score of 7.8), an integer overflow vulnerability in the kernel that could allow an attacker with access to a privileged binary to escalate their privileges to root. Qualys, which discovered and reported the vulnerability, said in September 2018 that exploitation was possible on systems with at least 32GB of RAM, due to attack requirements. There appear to be no reports of CVE-2018-14634’s in-the-wild exploitation prior to CISA’s warning. On Monday, CISA also added to the KEV catalog two SmarterMail bugs reported as exploited last week, and a Microsoft Office zero-day, urging federal agencies to address all five bugs by February 16. Related: Organizations Warned of Exploited Zimbra Collaboration Vulnerability Related: Cisco Patches Vulnerability Exploited by Chinese Hackers Related: Critical HPE OneView Vulnerability Exploited in Attacks Related: WatchGuard Patches Firebox Zero-Day Exploited in the Wild
securityweek.comJan 27, 2026extracted
Operational Summary - dicembre 2025
Operational Summary - dicembre 2025 Operational Summary - dicembre 2025 Pubblicazione PL02/260126/CSIRT-ITA Torna l’appuntamento mensile di CSIRT Italia sull’analisi e l’andamento della minaccia cyber con l’elenco delle vulnerabilità informatiche più gravi. Di seguito i principali punti emersi nel mese: Nel mese di dicembre 2025 sono stati registrati 158 eventi, in diminuzione del 13% rispetto ai 182 di novembre, così come il numero di incidenti (45) è in diminuzione del 24% rispetto al mese precedente. I settori con il maggior numero di vittime di eventi cyber registrate nel mese sono stati: Telecomunicazioni, Tecnologico e Vendita al dettaglio. Nel mese di dicembre 2025, l’attività riconducibile alla matrice hacktivista registra una ulteriore contrazione, in continuità con il trend di riduzione già osservato nei mesi precedenti. A dicembre 2025 l’attivismo rappresenta circa il 10% degli eventi complessivamente monitorati, in netta diminuzione rispetto al 31% rilevato nel mese di novembre. Nel mese di dicembre 2025 si è osservato un incremento degli eventi di esposizione di dati, prevalentemente riconducibile al rinvenimento di credenziali compromesse su piattaforme di scambio illecito, nonché alla pubblicazione di campioni di dati (data leak sample) da parte di gruppi ransomware, utilizzati sia quali elementi di prova dell’avvenuta compromissione sia come strumenti di pressione nell’ambito dell’attività di estorsione. In tali circostanze, il CSIRT Italia ha provveduto ad avvertire i soggetti potenzialmente interessati. L’attività di monitoraggio della superficie esposta dei soggetti italiani ha permesso di rinvenire 6.214 servizi a rischio, in quanto presentavano prodotti potenzialmente vulnerabili, per i quali sono state inviate 858 comunicazioni di allertamento. In particolar modo si evidenzia la CVE-2025-55182 relativa a Meta React Server in ragione della sua elevata criticità. La vulnerabilità interessava componenti applicativi basati su React Server Components, ampiamente utilizzati nello sviluppo di servizi web esposti su rete, e poteva essere sfruttata da remoto, da attaccanti non autenticati, con il rischio di esecuzione di codice arbitrario (Remote Code Execution) sui sistemi vulnerabili. Nel medesimo contesto, si segnalano altresì la vulnerabilità WatchGuard Fireware OS (CVE-2025-1473) e un insieme di vulnerabilità afferenti alla piattaforma Moodle (CVE-2025-67847, CVE-2025-67848, CVE-2025-67849, CVE-2025-67850, CVE-2025-67855), che hanno assunto rilievo in considerazione dell’elevato numero di soggetti coinvolti e delle evidenze di sfruttamento attivo in rete. Tali vulnerabilità hanno inoltre determinato un aumento del numero di sistemi e servizi potenzialmente vulnerabili rilevati, con conseguente incremento delle comunicazioni di allertamento, effettuate dall’Agenzia ai sensi dell’art. 2, comma 1, della Legge n. 90/2024, finalizzate a favorire l’adozione tempestiva di interventi risolutivi da parte dei soggetti interessati. L’analisi dei log provenienti da malware di tipo infostealer ha consentito, nel mese, di identificare 67 account potenzialmente compromessi, afferenti a soggetti istituzionali, tutti prontamente allertati. I vettori di attacco maggiormente rilevati a dicembre 2025 sono stati l’utilizzo di account validi, le e-mail e lo sfruttamento di vulnerabilità di note. Sono state pubblicate 5.635 nuove CVE, in aumento (+2.520) rispetto a novembre. Di queste, 755 presentano almeno un Proof of Concept (PoC), in aumento (+270), e per 14 CVE è stato rilevato lo sfruttamento attivo, in aumento (+9) rispetto a novembre. Le comunicazioni dirette, effettuate dal CSIRT Italia per segnalare potenziali compromissioni o fattori di rischio ad amministrazioni ed imprese italiane, nel mese di dicembre 2025 sono state in totale 2.986, in sensibile aumento rispetto a novembre.
acn.gov.itJan 27, 2026extracted
Critical HPE OneView Vulnerability Exploited in Attacks
The US cybersecurity agency CISA on Wednesday warned that a critical-severity vulnerability in the OneView product from Hewlett Packard Enterprise (HPE) has been exploited in attacks. Tracked as CVE-2025-37164 (CVSS score of 10/10), the security defect was disclosed on December 17, 2025, when HPE released hotfixes for it. HPE credited Nguyen Quoc Khanh for reporting the bug but refrained from sharing technical information. “This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution,” HPE said. According to cybersecurity firm Rapid7, the issue likely impacts a specific REST API endpoint reachable without authentication. On Wednesday, CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, warning that it has been exploited in the wild. “Hewlett Packard Enterprise OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution,” the cybersecurity agency notes. CISA has not shared details on the observed attacks. On Wednesday, the agency also added to the KEV list a code injection defect in Microsoft Office that was disclosed in 2009. Tracked as CVE-2009-0556, the bug was exploited in espionage campaigns against the Uyghur ethnic group in China over a decade ago. Per Binding Operational Directive (BOD) 22-01, federal agencies have three weeks to identify vulnerable HPE OneView and Microsoft Office instances in their environments and patch them. While BOD 22-01 only applies to federal agencies, all organizations are advised to review CISA’s KEV catalog and apply mitigations and patches for the vulnerabilities in it. Related: Hackers Exploit Zero-Day in Discontinued D-Link Devices Related: Fresh MongoDB Vulnerability Exploited in Attacks Related: WatchGuard Patches Firebox Zero-Day Exploited in the Wild Related: Vulnerability in Totolink Range Extender Allows Device Takeover
securityweek.comJan 8, 2026extracted
ACN: il report di novembre conferma un quadro di minaccia “a fisarmonica”
Secondo il rapporto mensile di CSIRT Italia, a novembre gli eventi cyber sono in calo a doppia cifra. “Il nuovo operational summary dell’ACN conferma un quadro di minaccia ‘a fisarmonica’”, commenta Pierluigi Paganini, analista di cyber security e Ceo Cybhorus. In particolare, secondo Dario Fadda, esperto di cyber sicurezza e collaboratore di Cybersecurity360, “emerge un dato: calano gli eventi segnalati, ma crescono gli incidenti con impatto confermato, segno che la pressione offensiva si sposta sempre più sulla qualità degli attacchi, non sulla quantità“. Indice degli argomenti Dal nuovo rapporto mensile dell’ACN emerge che “a novembre 2025 gli eventi cyber monitorati scendono a 182 (-32% rispetto a ottobre), ma restano concentrati su PA centrale, PA locale e Telco, settori strutturalmente esposti”, come osserva Paganini. Infatti, il numero di eventi cyber calano rispetto ai 267 del mese precedente. Invece gli incidenti (54) aumentano del 13% rispetto ad ottobre. E Pubblica amministrazione centrale, PA locale e Tlc rimangono i settori più colpiti ovvero rilevano il numero più alto di vittime di eventi cyber. Inoltre, gli attacchi attribuibili all’hacktivism sono passati dal 49% del mese precedente al 31% degli eventi complessivi di novembre. “Interessante è infatti il calo dell’hacktivism, in controtendenza rispetto al Rapporto Clusit 2025, che indica l’hacktivismo come vettore dominante in Italia (54% degli attacchi noti nel primo semestre)”, secondo Pierluigi Paganini. Il CSIRT Italia afferma che l’andamento è riconducibile al calo degli attacchi di tipo DDoS registrati nel periodo, che, prevalentemente, riguardano il settore dei Trasporti e la PA, non solo a livello locale, ma anche centrale. In questo ambito, attacchi DDoS sono sferrati contro siti internet di talune società di gestione aeroportuale, operanti su differenti scali nazionali: hanno causato temporaneamente inaccessibilità dei servizi web, indisponibilità che si limitano a intervalli di alcuni minuti. “PA centrale e locale, trasporti e telecomunicazioni confermano che il perimetro critico nazionale è ormai bersaglio strutturale, con il DDoS che torna a essere rumore di fondo più che fenomeno straordinario, pur colpendo nodi sensibili come la gestione aeroportuale”, mette in guardia Dario Fadda. Nello stesso quadro, e in linea con le osservazioni dei mesi scorsi, CSIRT Italia ha rilevato rivendicazioni di compromissioni di interfacce di sistemi SCADA, associati a piccole aziende del settore manifatturiero. Le realtà, possibilmente coinvolte, ricevono prontamente le informazioni, permettendo così di effettuare le verifiche tecniche necessarie e di mitigare i rischi cyber. Per monitorare la superficie esposta dei soggetti italiani, l’ACN ha spedito 423 comunicazioni di allerta a pubbliche amministrazioni e aziende che contavano 614 servizi Internet a rischio, con prodotti potenzialmente vulnerabili. Gli alert riguardavano soprattutto le CVE di WatchGuard Firebox (CVE-2025-59396) e SolarWinds Web Help Desk (CVE-2025-40549, CVE-2025-40548 e CVE-2025-40547). Analizzando i log derivanti dagli infostealer, è stata possibile l’identificazione di 112 account riconducibili a soggetti istituzionali, tutti tempestivamente allertati. “Preoccupano, da un lato, la persistenza di minacce avanzate come le varianti di BadCandy su Cisco IOS XE e lo sfruttamento mirato di vulnerabilità in prodotti di larga diffusione (WatchGuard, SolarWinds, stack open source), dall’altro l’emersione costante di superfici esposte e account compromessi tramite infostealer, che raccontano un Paese ancora troppo lento nel chiudere ciò che non dovrebbe essere esposto“, avverte Dario Fadda. Inoltre, le attività di monitoraggio proattivo hanno rilevato una nuova attività malevola per installare varianti aggiornate della webshell nota come BadCandy, legata a minacce di tipo evoluto e la cui osservazione risale all’ottobre 2023, con potenziale impatto su prodotti Cisco IOS XE esposti in rete. “I dati ACN sul monitoraggio proattivo, 423 allertamenti per 614 servizi esposti e 1.420 comunicazioni CSIRT Italia, mostrano un’azione preventiva sempre più matura, coerente con la traiettoria delineata da ENISA Threat Landscape 2025, che invita a passare da difesa ‘di perimetro’ a modelli intelligence driven e zero trust“. Queste evidenze hanno portato ad analizzare il rischio in maniera mirata, valutando la diffusione sul territorio nazionale di questo impianto malevolo. difesa sempre più industrializzata I vettori di attacco più monitorati a novembre 2025 sono risultati le mail, l’uso di account validi e lo sfruttamento di vulnerabilità già conosciute. Le nuove CVE sono inoltre a quota 3.115, in netto calo rispetto al mese precedente (−1.269). A novembre 2025, il CSIRT Italia ha infine eseguito 1.420 comunicazioni dirette, in declino rispetto ad ottobre, per avvertire amministrazioni ed aziende italiane di eventuali compromissioni o fattori di rischio. “Il volume di comunicazioni di allertamento e la proattività del CSIRT Italia restituiscono l’immagine di una difesa sempre più industrializzata, ma anche la necessità urgente di fare il salto da risposta reattiva a igiene digitale di base sistemica“, sottolinea Dario Fadda. Molto “importante è la recente introduzione da parte di ACN del referente CSIRT, nominabile per ogni organizzazione del perimetro: azione che aumenterà l’efficienza e tempestività delle segnalazioni di incidente a livello Italia”, conclude Dario Fadda.
cybersecurity360.itDec 30, 2025extracted
Fresh MongoDB Vulnerability Exploited in Attacks
Threat actors started exploiting a high-severity MongoDB vulnerability shortly after proof-of-concept (PoC) code and technical details were released. Tracked as CVE-2025-14847, the flaw impacts the Zlib compression protocol and allows attackers to read uninitialized heap memory without authentication. Patches for the bug were released on December 19, when MongoDB warned that successful exploitation could lead to memory leaks. Dubbed MongoBleed, the issue can be abused via crafted compressed messages that, when parsed, cause the server to return the amount of allocated memory, and not the length of the decompressed data. On Christmas Eve, Ox Security published a technical analysis of the security defect, explaining how it could be exploited to extract sensitive information from MongoDB servers. Two days later, Elastic Security’s Joe Desimone released a PoC exploit for it, which can be used to extract session tokens, passwords, API keys, and other sensitive data. Ox Security says the MongoDB vulnerability can be exploited to leak entire databases by sending multiple malformed requests. According to Wiz, because the flawed network message decompression logic is processed before authentication, attackers can leak fragments of sensitive in-memory data without valid credentials or user interaction. “Because the vulnerability is reachable prior to authentication and does not require user interaction, Internet-exposed MongoDB servers are particularly at risk,” Wiz notes. MongoBleed exploited in the wild Warning that the exploitation of MongoBleed started shortly after the PoC exploit was released, Wiz notes that roughly 42% of cloud environments have MongoDB instances that are vulnerable. Censys observed more than 87,000 vulnerable MongoDB servers globally. According to security researcher Kevin Beaumont, there are over 200,000 instances. “Because of how simple this is now to exploit — the bar is removed — expect high likelihood of mass exploitation and related security incidents,” Beaumont notes. The vulnerability was patched in MongoDB versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30. Organizations should update self-managed instances as soon as possible or disable Zlib compression on the server to prevent exploitation. Before updating, however, administrators should hunt for signs of compromise by checking the MongoDB server logs, Recon InfoSec co-founder Eric Capuano notes. Related: WatchGuard Patches Firebox Zero-Day Exploited in the Wild Related: CISA Warns of Exploited Flaw in Asus Update Tool Related: SonicWall Patches Exploited SMA 1000 Zero-Day Related: Gladinet CentreStack Flaw Exploited to Hack Organizations
securityweek.comDec 29, 2025extracted
Week in review: WatchGuard Firebox firewalls attacked, infosec enthusiasts targeted with fake PoCs
Week in review: WatchGuard Firebox firewalls attacked, infosec enthusiasts targeted with fake PoCs Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Building cyber talent through competition, residency, and real-world immersion In this Help Net Security interview, Chrisma Jackson, Director of Cybersecurity & Mission Computing Center and CISO at Sandia National Laboratories, reflects on where the cyber talent pipeline breaks down and what it takes to fix it. She discusses skill gaps, hiring and retention realities, and how cybersecurity careers are evolving beyond traditional paths. WatchGuard Firebox firewalls under attack (CVE-2025-14733) More than 115,000 internet-facing WatchGuard Firebox firewalls may be vulnerable to compromise via CVE-2025-14733, a remote code execution vulnerability actively targeted by attackers, Shadowserver’s latest scanning reveals. Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits Malware peddlers are targeting infosec enthusiasts, budding security professionals, and aspiring hackers with the Webrat malware, masquerading the threat as proof-of-concept (PoC) exploits for known vulnerabilities. DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists Resecurity has identified the emergence of uncensored darknet AI assistants, enabling threat actors to leverage advanced data processing capabilities for malicious purposes. One of these – DIG AI – was identified on September 29 of this year and has already gained popularity among cybercriminal and organized crime circles. Five identity-driven shifts reshaping enterprise security in 2026 Delinea leaders predict that 2026 will force a new identity security playbook, one built for a world where AI systems, machine identities, and autonomous agents outnumber humans, operate at machine speed, and increasingly make decisions beyond direct human oversight. Session tokens give attackers a shortcut around MFA In this Help Net Security video, Simon Wijckmans, CEO at cside, discusses why session token theft is rising and why security teams miss it. He walks through how web applications rely on browsers to store session tokens after login often in cookies or browser storage. Any script running on the page can reach those tokens including ads analytics tools and marketing tags. NIST issues guidance on securing smart speakers Smart home devices, such as voice-activated digital assistants, are increasingly used in home health care, with risks involved. An attacker could change a prescription, steal medical data, or connect a patient to an impostor. To reduce cybersecurity risks tied to this use, NIST has released guidelines to help protect patients and providers. Anubis: Open-source web AI firewall to protect from scraper bots Anubis is an open-source tool designed to protect websites from automated scraping and abusive traffic by adding computational friction before a request is served. Maintained by TecharoHQ, the project targets a growing problem for site operators who want to keep content accessible to humans while limiting large scale automated collection. Browser agents don’t always respect your privacy choices Browser agents promise to handle online tasks without constant user input. They can shop, book reservations, and manage accounts by driving a web browser through an AI model. A new academic study warns that this convenience comes with privacy risks that security teams should not ignore. Docker makes hardened images free open and transparent for everyone Docker has made its open source Docker Hardened Images project available at no cost for every developer and organization. The catalog contains more than 1,000 container images built on open source distributions such as Debian and Alpine and is released under the Apache 2.0 license. The images are accessible through Docker Hub and related distribution points. Formal proofs expose long standing cracks in DNSSEC DNSSEC is meant to stop attackers from tampering with DNS answers. It signs records so resolvers can verify that data is authentic and unchanged. Many security teams assume that if DNSSEC validation passes, the answer can be trusted. New academic research suggests that assumption deserves closer scrutiny. Weak enforcement keeps PCI DSS compliance low Payment card breaches continue to surface across industries, even after years of investment in security standards. A new study links this pattern to enforcement, showing that PCI DSS compliance trails behind HIPAA, GDPR, and the EU’s NIS2 Directive. Conjur: Open-source secrets management and application identity Conjur is an open-source secrets management project designed for environments built around containers, automation, and dynamic infrastructure. It focuses on controlling access to credentials such as database passwords, API keys, and tokens that applications need at runtime. The project is maintained in the open and developed with input from a user and contributor base. What if your face could say “don’t record me”? Researchers think it’s possible Phones, smart glasses, and other camera-equipped devices capture scenes that include people who never agreed to be recorded. A newly published study examines what it would take for bystanders to signal their privacy choices directly to nearby cameras. From AI to cyber risk, why IT leaders are anxious heading into 2026 Cybersecurity threats are shaping IT planning for 2026, with AI maturity and regulation emerging as another major source of disruption, according to a global survey from Veeam. LLMs can assist with vulnerability scoring, but context still matters Every new vulnerability disclosure adds another decision point for already stretched security teams. A recent study explores whether LLMs can take on part of that burden by scoring vulnerabilities at scale. While the results show promise in specific areas, consistent weaknesses continue to hold back fully automated scoring. 574 arrests, $3 million recovered in Africa-wide cybercrime crackdown Law enforcement agencies across 19 countries arrested 574 suspects and recovered approximately $3 million during a major cybercrime operation spanning Africa. Cloud security is stuck in slow motion Cloud environments are moving faster than the systems meant to protect them. A new Palo Alto Networks study shows security teams struggling to keep up with development cycles, growing cloud sprawl, and attacker tactics that now compress breaches into minutes instead of weeks. AI code looks fine until the review starts Software teams have spent the past year sorting through a rising volume of pull requests generated with help from AI coding tools. New research puts numbers behind what many reviewers have been seeing during work. What happens to enterprise data when GenAI shows up everywhere Generative AI is spreading across enterprise workflows, shaping how employees create, share, and move information between systems. Security teams are working to understand where data ends up, who can access it, and how its use reshapes security assumptions. This article explores how GenAI is increasing data exposure, creating new threats, and outpacing existing policies, controls, and testing. Counterfeit defenses built on paper have blind spots Counterfeit protection often leans on the idea that physical materials have quirks no attacker can copy. A new study challenges that comfort by showing how systems built on paper surface fingerprints can be disrupted or bypassed. Elementary OS 8.1 rolls out with a stronger focus on system security Elementary OS 8.1 is now available for download and shipping on select hardware from retailers such as Star Labs, Slimbook, and Laptop with Linux. The update arrives after more than a year of refinements based on community feedback and issue reports. Governance maturity defines enterprise AI confidence AI security has reached a point where enthusiasm alone no longer carries organizations forward. New Cloud Security Alliance research shows that governance has become the main factor separating teams that feel prepared from those that do not. The next big IT security battle is all about privileged access Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in 2026 driven by new realities of cybersecurity, hybridization, AI, and more. NASLOV Cybersecurity jobs available right now: December 23, 2025 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
helpnetsecurity.comDec 28, 2025extracted
Operational Summary - novembre 2025
Operational Summary - novembre 2025 Operational Summary - novembre 2025 Pubblicazione PL01/251223/CSIRT-ITA Torna l’appuntamento mensile di CSIRT Italia sull’analisi e l’andamento della minaccia cyber con l’elenco delle vulnerabilità informatiche più gravi. Di seguito i principali punti emersi nel mese: Nel mese di novembre 2025 sono stati registrati 182 eventi, in diminuzione del 32% rispetto ai 267 di ottobre, mentre il numero di incidenti (54) è in aumento del 13% rispetto al mese precedente. I settori con il maggior numero di vittime di eventi cyber registrate nel mese sono stati: Pubblica amministrazione centrale, Pubblica amministrazione locale e Telecomunicazioni. Nel corso del mese di novembre 2025, l’attività riconducibile alla matrice hacktivista si è attestata su livelli inferiori rispetto al mese precedente, rappresentando il 31% degli eventi complessivamente monitorati, a fronte del 49% registrato nel mese di ottobre. Tale andamento risulta associato alla riduzione degli attacchi di tipo DDoS rilevati nel periodo, che hanno interessato in via prevalente il settore dei Trasporti e la Pubblica Amministrazione, sia a livello locale sia centrale. In tale contesto, sono stati osservati attacchi DDoS ai danni dei siti web di alcune società di gestione aeroportuale, che operano su diversi scali del territorio nazionale, con temporanee indisponibilità dei servizi web, limitate a intervalli di alcuni minuti. All’interno dello stesso quadro, e in linea con quanto già osservato nei mesi precedenti, sono state rilevate rivendicazioni di compromissioni di interfacce di sistemi SCADA, riferibili a piccole imprese del comparto manifatturiero. I soggetti potenzialmente coinvolti sono stati tempestivamente informati, per consentire le necessarie verifiche tecniche e l’adozione delle eventuali misure di mitigazione. Nell’ambito dell’attività di monitoraggio della superficie esposta dei soggetti italiani sono state inviate 423 comunicazioni di allertamento a pubbliche amministrazioni e imprese che esponevano su Internet 614 servizi a rischio, in quanto presentavano prodotti potenzialmente vulnerabili, in particolar modo alle CVE di WatchGuard Firebox (CVE-2025-59396) e SolarWinds Web Help Desk (CVE-2025-40549, CVE-2025-40548 e CVE-2025-40547). Sempre nell’ambito delle attività di monitoraggio proattivo, è stata rilevata una nuova attività malevola finalizzata all’installazione di varianti aggiornate della webshell denominata BadCandy, associata a minacce di tipo avanzato e osservata per la prima volta nel mese di ottobre 2023, con possibile impatto su prodotti Cisco IOS XE esposti in rete. A seguito di tali evidenze, è stata condotta un’analisi mirata volta a valutare la diffusione sul territorio nazionale del suddetto impianto malevolo. L’analisi dei log provenienti da malware di tipo infostealer ha consentito, nel mese, di dentificare 112 account afferenti a soggetti istituzionali, tutti prontamente allertati. I vettori di attacco maggiormente rilevati a novembre 2025 sono stati le e-mail, l’utilizzo di account validi e lo sfruttamento di vulnerabilità di note. Sono state pubblicate 3.115 nuove CVE, in sensibile diminuzione rispetto ad ottobre (−1.269). Le comunicazioni dirette, effettuate dal CSIRT Italia per segnalare potenziali compromissioni o fattori di rischio ad amministrazioni ed imprese italiane, nel mese di novembre 2025 sono state 1.420, in diminuzione rispetto ad ottobre.
acn.gov.itDec 23, 2025extracted
22nd December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES An adult content platform PornHub has disclosed a data breach linked to analytics provider Mixpanel. The breach exposed more than 200 million records related to Premium users, including email addresses, search, watch, and download histories, locations, and associated video details collected prior to 2021. Pornhub stated that no passwords, payment information, or government-issued IDs were compromised. OpenAI also acknowledged a related incident that was caused by compromise of Mixpanel. The breach has been attributed to the ShinyHunters extortion group. SoundCloud, an online audio streaming platform, has confirmed a cyber attack that resulted in threat actors gaining unauthorized access to a database containing users’ email addresses and public profile information. The breach affected approximately 20% of SoundCloud’s users, which might impact 28 million accounts, and caused outages and VPN connection issues. The ShinyHunters extortion gang has claimed responsibility for this attack. Autoparts giant LKQ has acknowledged a cyberattack tied to the Oracle E-Business Suite compromise. The company said personal data of over 9,070 people, including Employer Identification Numbers and Social Security numbers, was exposed. Check Point IPS provides protection against this threat (Oracle Multiple Products Remote Code Execution) DXS International, a British NHS technology supplier, has encountered a cyber-attack on December 14th that resulted in unauthorized access to its internal office servers, affecting internal systems but not disrupting clinical services. It remains unclear whether NHS patient data was compromised. The University of Sydney has suffered a data breach that resulted in hackers gaining access to an online coding repository and stealing files containing personal information of staff and students. Over 27,000 individuals were affected, including names, dates of birth, phone numbers, home addresses, and job details for current and former staff, students, alumni, and affiliates. Petróleos de Venezuela (PDVSA), Venezuela’s state oil company, has experienced a cyberattack that resulted in disruptions to its export operations and offline systems managing the country’s main crude terminal. The incident affected administrative and operational network systems, leading to a halt in cargo deliveries. The scope of data or user information compromised has not been disclosed. Denmark’s water utility has experienced a cyber attack that resulted in a disruption of critical water infrastructure systems. The attack impacted operational control systems supporting essential services, forming part of a broader campaign of attacks targeting Denmark’s critical infrastructure and electoral environment. The Danish Defence Intelligence Service attributed the incident to the Russia affiliated group Z-Pentest. VULNERABILITIES AND PATCHES Critical severity vulnerability with a CVSS score of 10.0 was disclosed in HPE OneView Software. The flaw, CVE-2025-37164, allows unauthenticated remote code execution and affects all versions prior to 11.00, including versions 5.20 through 10.20. Successful exploitation could enable a remote attacker to execute arbitrary code on affected centralized IT infrastructure management systems. Check Point IPS provides protection against this threat (HPE OneView Remote Code Execution (CVE-2025-37164)) A critical remote code execution vulnerability, CVE-2025-14733, in WatchGuard Firebox firewalls running Fireware OS 11.x and later is being actively exploited. The out-of-bounds write flaw enables unauthenticated remote code execution on unpatched devices with IKEv2, without user interaction. Researchers spotted active exploitation of CVE-2025-59718 and CVE-2025-59719, critical authentication bypass flaws in Fortinet FortiGate, FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Attackers can log in without credentials and export full device configurations, risking cracked passwords. THREAT INTELLIGENCE REPORTS Check Point Research revealed a sophisticated wave of attacks attributed to the Chinese threat actor Ink Dragon, which targets European governments while continuing campaigns in Southeast Asia and South America. The threat actor converts compromised IIS servers into relay nodes with ShadowPad, exploits predictable configuration keys for access, and deploys a new FinalDraft backdoor for exfiltration and lateral movement. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research analyzed GachiLoader, a Node.js–based malware loader observed in a campaign linked to the YouTube Ghost Network. The campaign is notable for extensive obfuscation and a previously undocumented PE injection technique. GachiLoader deploys a second-stage loader, Kidkadi, which abuses Vectored Exception Handling (VEH) in a novel method, dubbed Vectored Overloading, to load its malicious payload. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research noticed a surge in darknet campaigns recruiting insiders at banks, crypto exchanges, telecoms, and major tech firms to sell access and data. Listings advertise payouts of $3,000 to $15,000, offer datasets like 37 million records for $25,000, and solicit telecom staff for SIM swapping to bypass two-factor authentication. Check Point researchers updated on a global surge in AI-driven holiday scams across phishing, fake retail sites, and social media giveaways. They recorded 33,502 phishing emails in two weeks and over 10,000 daily ads impersonating delivery brands like Royal Mail, FedEx, UPS and DPD, while AI chatbots help fraudulent stores appear credible.
research.checkpoint.comDec 22, 2025extracted
⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More
Cyber threats last week showed how attackers no longer need big hacks to cause big damage. They’re going after the everyday tools we trust most — firewalls, browser add-ons, and even smart TVs — turning small cracks into serious breaches. The real danger now isn’t just one major attack, but hundreds of quiet ones using the software and devices already inside our networks. Each trusted system can become an entry point if it’s left unpatched or overlooked. Here’s a clear look at the week’s biggest risks, from exploited network flaws to new global campaigns and fast-moving vulnerabilities. ⚡ Threat of the Week Flaws in Multiple Network Security Products Come Under Attack — Over the past week, Fortinet, SonicWall, Cisco, and WatchGuard said vulnerabilities in their products have been exploited by threat actors in real-world attacks. Cisco said attacks exploiting CVE-2025-20393, a critical flaw in AsyncOS, have been abused by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686 to deliver malware such as ReverseSSH (aka AquaTunnel), Chisel, AquaPurge, and AquaShell. The flaw remains unpatched. SonicWall said attacks exploiting CVE-2025-40602, a local privilege escalation flaw impacting Secure Mobile Access (SMA) 100 series appliances, have been observed in connection with CVE-2025-23006 (CVSS score 9.8) to achieve unauthenticated remote code execution with root privileges. The development comes as firewalls and edge appliances have become a favorite target for attackers, giving attackers deeper visibility into traffic, VPN connections, and downstream systems. Cyber Forum 2026: Adversary Trends, AI Innovation, and the Future of Security Ops A virtual cybersecurity forum for today’s security leaders. Discover how AI and automation strengthen defenses, streamline operations, and deliver measurable business impact. Hear from security leaders and research experts and get actionable strategies and trends. Register for free today. Secure Your Seat ➝ 🔔 Top News Featured Chrome Extension Caught Harvesting AI Chats — Urban VPN Proxy, a Google Chrome and Microsoft Edge extension, with more than 7.3 installations, was observed stealthily gathering every prompt entered by users into artificial intelligence (AI)-powered chatbots like OpenAI ChatGPT, Anthropic Claude, Microsoft Copilot, DeepSeek, Google Gemini, xAI Grok, Meta AI, and Perplexity. Three other extensions from the same developer, 1ClickVPN Proxy, Urban Browser Guard, and Urban Ad Blocker, were also updated with similar functionality. Collectively, these add-ons were installed more than eight million times. The extensions are no longer available for download from the Chrome Web Store. Ink Dragon Targets Governments with ShadowPad and FINALDRAFT — The threat actor known as Jewelbug (CL-STA-0049, Earth Alux, Ink Dragon, and REF7707) has been increasingly focusing on government targets in Europe since July 2025, even as it continues to attack entities located in Southeast Asia and South America. The campaign has "impacted several dozen victims, including government entities and telecommunications organizations, across Europe, Asia, and Africa." Ink Dragon does not merely use victims for data theft but actively repurposes them to support ongoing operations against other targets of interest. This creates a self-sustaining infrastructure that obscures the true origin of the attacks while maximizing the utility of every compromised asset. Kimwolf Botnet Hijacks 1.8 Million Android TVs — A new botnet named Kimwolf is powered by no less than 1.8 million Android TVs. Infections are scattered globally, with Brazil, India, the U.S., Argentina, South Africa, and the Philippines registering higher concentrations. Kimwolf is believed to share its origins with AISURU, which has been behind some of the record-breaking DDoS attacks over the past year. It's suspected that the attackers reused code from AISURU in the early stages, before opting to develop the Kimwolf botnet to evade detection. QiAnXin XLab said it's possible some of these attacks may not have come from AISURU alone, and that Kimwolf may be either participating or even leading the efforts. LongNosedGoblin Uses Group Policy For Malware Deployment — A previously undocumented China-aligned threat cluster dubbed LongNosedGoblin has been attributed to a series of cyber attacks targeting governmental entities in Southeast Asia and Japan. Central to the group's tradecraft is the abuse of Group Policy to deploy malware across the compromised network and cloud services for communication with infected endpoints using a backdoor dubbed NosyDoor. The threat actor is believed to be active since at least September 2023. The exact initial access methods used in the attacks are presently unknown. Kimsuky Uses DocSwap Android Malware — The North Korean threat actor known as Kimsuky has been linked to a new campaign that distributes a new variant of Android data gathering malware called DocSwap via QR codes hosted on phishing sites mimicking Seoul-based logistics firm CJ Logistics (formerly CJ Korea Express). The apps masquerade as package delivery service apps. It's believed that the threat actors are using smishing texts or phishing emails impersonating delivery companies to deceive recipients into clicking on booby-trapped URLs hosting the apps. A noteworthy aspect of the attack is its QR code-based mobile redirection, which prompts users visiting the URLs from a desktop computer to scan a QR code displayed on the page on their Android device to install the supposed shipment tracking app and look up the status. ️🔥 Trending CVEs Hackers act fast. They can use new bugs within hours. One missed update can cause a big breach. Here are this week’s most serious security flaws. Check them, fix what matters first, and stay protected. This week’s list includes — CVE-2025-14733 (WatchGuard), CVE-2025-11901, CVE-2025-14302, CVE-2025-14303, CVE-2025-14304 (pre-boot DMA protection Bypass), CVE-2025-37164 (HPE OneView Software), CVE-2025-59374 (ASUS Live Update), CVE-2025-20393 (Cisco AsyncOS), CVE-2025-40602 (SonicWall SMA 100 Series), CVE-2025-66430 (Plesk), CVE-2025-33213 (NVIDIA Merlin Transformers4Rec for Linux), CVE-2025-33214 (NVIDIA NVTabular for Linux), CVE-2025-54947 (Apache StreamPark), CVE-2025-13780 (pgAdmin), CVE-2025-34352 (JumpCloud Agent), CVE-2025-14265 (ConnectWise ScreenConnect), CVE-2025-40806, CVE-2025-40807 (Siemens Gridscale X Prepay), CVE-2025-32210 (NVIDIA Isaac Lab), CVE-2025-64374 (Motors WordPress theme), CVE-2025-64669 (Microsoft Windows Admin Center), CVE-2025-46295 (Apache Commons Text), CVE-2025-68154 (systeminformation), CVE-2025-14558 (FreeBSD), and cross-site scripting and information disclosure flaws in Roundcube Webmail (no CVEs). 📰 Around the Cyber World FBI Warns of Campaigns Impersonating Government Officials — The U.S. Federal Bureau of Investigation (FBI) has warned that malicious actors have impersonated senior U.S. state government, White House, and Cabinet-level officials, as well as members of Congress, to target individuals, including officials' family members and personal acquaintances, since at least 2023. The "Malicious actors have sent text messages and AI-generated voice messages — techniques known as smishing and vishing, respectively — that claim to come from a senior U.S. official to establish rapport with targeted individuals," the FBI said. "In the scheme, actors contact an individual and briefly engage on a topic the victim is versed on, with a request to move communication to a secondary, encrypted mobile messaging application, happening almost immediately." Once the conversation has shifted to Signal or WhatsApp, the threat actors urge victims to provide an authentication code that allows the actors to sync their device with the victim's contact list, share Personally Identifiable Information (PII) and copies of sensitive personal documents, wire funds to an overseas financial institution under false pretenses, and request them to introduce the actor to a known associate. Noyb Files Complaint Against TikTok, AppsFlyer and Grindr — Austrian privacy non-profit noyb has filed complaints against TikTok, AppsFlyer, and Grindr, accusing the popular video sharing platform of unlawfully tracking users across apps in violation of GDPR laws in the region. "A user found out about this unlawful tracking practice through an access request -- which showed that, e.g. his usage of Grindr was sent to TikTok, likely via the Israeli tracking company AppsFlyer -- which allows TikTok to draw conclusions about his sexual orientation and sex life," noyb said. "TikTok initially even withheld this information from the user, which violates Article 15 GDPR. Only after repeated inquiries, TikTok revealed that it knows which apps he used, what he did within these apps (for example, adding a product to the shopping cart) - and that this data also included information about his usage of the gay dating app Grindr." AuraStealer Spotted in the Wild — An emerging malware-as-a-service (MaaS) information stealer called AuraStealer has been distributed via Scam-Yourself campaigns, where victims are lured by TikTok videos disguised as product activation guides. "Viewers are instructed to manually retype and run a displayed command in an administrative PowerShell, which, however, instead of activating the software, quietly downloads and executes the malicious payload," Gen Digital said. "Apart from TikTok Scam-Yourself campaigns, AuraStealer is also distributed through supposedly cracked games or software, with delivery chains of varying complexity." AuraStealer makes use of a long list of anti-analysis and obfuscation techniques, including indirect control flow obfuscation, string encryption, and exception-driven API hashing, to resist attempts to reverse engineer the malware. It's capable of harvesting data from Chromium- and Gecko-based browsers, cryptocurrency wallets from desktop applications and browser extensions, clipboard contents, session tokens, credentials, VPNs, password managers, screenshots, and detailed system metadata. Also detected in the wild are two other information stealers named Stealka and Phantom, with the latter distributed via fake Adobe installers. Blind Eagle Continues to Attack Colombia — Colombian institutions have continued to face attacks from a threat actor known as Blind Eagle. The latest phishing attacks, targeting agencies under the Ministry of Commerce, Industry and Tourism (MCIT), have shifted to a more sophisticated, multi-layer flow that uses an off-the-shelf loader named Caminho to deliver DCRat. The messages are sent from compromised email accounts within the same organization to bypass security checks. "The phishing email used a legal-themed design to lure the recipient," Zscaler said. "The email was created to appear as an official message from the Colombian judicial system, referencing a labor lawsuit with an authentic-sounding case number and date. The email pressures the recipient to confirm receipt immediately, leveraging authority, fear of legal consequences, and confidentiality warnings to trick the recipient into taking an action, namely opening the attachment." Scripted Sparrow Linked to Large-Scale BEC Attacks — A sprawling Business Email Compromise (BEC) collective known as Scripted Sparrow has been observed distributing more than three million email messages each month and refining its social-engineering playbook. "The scale of the group's operation strongly suggests the use of automation to generate and send their attack messages," Fortra said. "The group utilizes a combination of free webmail addresses as well as addresses on domains they've registered specifically for their operations. The group operates by posing as various executive coaching and leadership training consultancies." First discovered in June 2024, the "loose collective of fraudsters" has members located in Nigeria, South Africa, Türkiye, Canada, and the U.S. The group is estimated to have registered 119 domains and used 245 webmail addresses. It has also used 256 bank accounts to move money out of victims' bank accounts. Smart Devices Run Outdated Browser Versions — An academic study by a team of Belgian researchers has found that a majority of smart devices, such as smart TVs, e-readers, and gaming consoles, come with an embedded web browser that runs extremely outdated versions, sometimes as much as three years. All five e-readers that were tested, and 24 of 35 smart TV models, used embedded browsers that were at least three years behind current versions available to users of desktop computers. These outdated, embedded browsers can leave users open to phishing and other security vulnerabilities. The authors said some of the issues lie in how development frameworks like Electron bundle browsers with other components. "We suspect that, for some products, this issue stems from the user-facing embedded browser being integrated with other UI components, making updates challenging – especially when bundled in frameworks like Electron, where updating the browser requires updating the entire framework," they said in the paper. "This can break dependencies and increase development costs." Denmark Blames Russia For Attack on Water Utility — The Danish Defence Intelligence Service (DDIS) has blamed Russia for recent destructive and disruptive cyber attacks against the country, including a water utility in 2024, as well as distributed denial-of-service (DDoS) attacks on Danish websites in the run-up to the 2025 municipal and regional council elections. The attacks have been attributed to pro-Russian hacktivist groups Z-Pentest and NoName057(16), respectively. "The Russian state uses both groups as instruments of its hybrid war against the West. The aim is to create insecurity in the targeted countries and to punish those who support Ukraine," the DDIS said. "Russia’s cyber operations form part of a broader influence campaign intended to undermine Western support for Ukraine." The statement comes a few days after a global cybersecurity advisory warned that pro-Russian hacktivist groups conduct opportunistic attacks against US and global critical infrastructure. Russia Targeted by Arcane Werewolf — Russian manufacturing companies have become the target of a threat actor known as Arcane Werewolf (aka Mythic Likho). Campaigns undertaken by the hacking group in October and November 2025 likely leveraged phishing emails as the initial access vector that presumably contained links to a malicious archive hosted on the attackers' server. The links directed victims to a spoofed website imitating a Russian manufacturing company. The end goal of the attacks is to deploy a custom implant named Loki 2.1 by means of a loader that's delivered using a Go-based dropper downloaded from an external server using PowerShell code embedded into a Windows shortcut (LNK) contained in the ZIP file. In an attack chain detected in November 2025, a new C++ dropper was used to propagate the malware. Loki 2.1 is equipped to upload/download files, inject code into a target process, terminate arbitrary processes, retrieve environment variables, and stop its own execution. RansomHouse Upgrades to Complex Encryption — The RansomHouse (aka Jolly Scorpius) ransomware group has upgraded its file encryption process to use two different encryption keys to encrypt files as part of their attacks in what has been described as a significant escalation and "concerning trajectory" in ransomware development. "The upgraded version's code reveals a two-factor encryption scheme where the file is encrypted with both a primary key and a secondary key. Data encryption is processed separately for each key," Palo Alto Networks Unit 42 said. "This significantly increases the difficulty of decrypting the data without both keys." The e-crime group has been active since December 2021, listing 123 victims on its data leak site. Central to the threat actor's operations is a tool called MrAgent that provides attackers with persistent access to a victim's environment and simplifies managing compromised hosts at scale. It's also responsible for deploying Mario to encrypt critical VM files in the ESXi hypervisor. LLMs and Ransomware Lifecycle — The emergence of large language models (LLMs) is likely accelerating the ransomware lifecycle, according to new findings from SentinelOne. "We observe measurable gains in speed, volume, and multilingual reach across reconnaissance, phishing, tooling assistance, data triage, and negotiation, but no step-change in novel tactics or techniques driven purely by AI at scale," the company said. LLMs, including those that are deployed locally, can be used to replace the manual effort associated with drafting phishing emails and localized content, search for sensitive data, and develop malicious code. The continued sightings of various dark LLMs show that criminals are gravitating toward uncensored models that allow them to evade guardrails. "Actors already chunk malicious code into benign prompts across multiple models or sessions, then assemble offline to dodge guardrails," SentinelOne said. "This workflow will become commoditized as tutorials and tooling proliferate, ultimately maturing into 'prompt smuggling as a service.'" The findings signal that the barrier to entry into cybercrime continues to drop, even as the ransomware ecosystem is splintering and the line between nation-state and crimeware activity is increasingly blurring. The use of the technology is also likely to blur existing assessment lines around tradecraft and attribution, owing to the fact that the capabilities even allow smaller groups to acquire capabilities that were once limited to advanced state-backed actors. TikTok Signs Agreement to Create New U.S. Joint Venture — Nearly a year after TikTok's operations were briefly banned in the U.S. for national security concerns, the popular video-sharing platform said it has finalized a deal to move a substantial portion of its U.S. business under a new joint venture named TikTok USDS Joint Venture LLC. According to reports from Axios, Bloomberg, CNBC, and The Hollywood Reporter, the company has signed agreements with the three managing investors: Oracle, Silver Lake, and Abu Dhabi-based MGX. Together, those companies will own 45% of the U.S. operation, while ByteDance retains a nearly 20% share. The new entity is said to be responsible for protecting U.S. data, ensuring the security of its prized algorithm, content moderation, and "software assurance." Oracle will be the trusted security partner in charge of auditing and validating compliance. The agreement is set to go into effect on January 22, 2026. Under a national security law, China-based ByteDance was required to divest TikTok's U.S. operations or face an effective ban in the country. The U.S. government has since extended the ban four times as a deal was being hatched behind the scenes. Under President Donald Trump's executive order in September, the attorney general was blocked from enforcing the national security law for a 120-day period in order to "permit the contemplated divestiture to be completed," allowing the deal to finalize by January 23, 2026. Android Adware Campaign Targets East and Southeast Asia — Android users in the Philippines, Pakistan, and Malaysia have been targeted by a large-scale Android adware campaign dubbed GhostAd that silently drains resources and disrupts normal phone use through persistent background activity. The set of 15 apps, distributed via Google Play, masqueraded as harmless utility and emoji-editing tools such as Vivid Clean and GenMoji Studio. "Behind their cheerful icons, these apps created a persistent background advertising engine – one that kept running even after users closed or rebooted their devices, quietly consuming battery and mobile data," Check Point said. "GhostAd integrates multiple legitimate advertising software development kits (SDKs), including Pangle, Vungle, MBridge, AppLovin, and BIGO, but uses them in a way that violates fair-use policies. Instead of waiting for user interaction, the apps continuously load, queue, and refresh ads in the background, using Kotlin coroutines to sustain the cycle." The apps have since been removed by Google, but not before they amassed millions of downloads. Texas Sues TV Makers for Spying on Owners — Texas Attorney General Ken Paxton accused Sony, Samsung, LG, Hisense, and TCL of spying on their customers and illegally collecting their data by using automatic content recognition (ACR), according to a new lawsuit. "ACR in its simplest terms is an uninvited, invisible digital invader," Paxton said. "This software can capture screenshots of a user’s television display every 500 milliseconds, monitor viewing activity in real time, and transmit that information back to the company without the user’s knowledge or consent. This conduct is invasive, deceptive, and unlawful." Cybercriminals Entice Insiders with High Payouts — Check Point has called attention to dark web posts that aim to recruit insiders within organizations to gain access to corporate networks, user devices, and cloud environments. The activity targets the financial sector and cryptocurrency firms, as well as companies like Accenture, Genpact, Netflix, and Spotify. The ads offer payouts from $3,000 to $15,000 for access or data. "Across darknet forums, employees are being approached, or even volunteering, to sell access or sensitive information for lucrative rewards," the company said. When internal staff disable defenses, leak credentials, or provide privileged information, preventing an attack becomes exponentially harder. Monitoring the deep web and darknet for organizational mentions or stolen data is now as critical as deploying advanced cyber prevention technologies." Flaws in Anno 1404 Game — Synacktiv researchers have disclosed multiple vulnerabilities in a strategy game named Anno 1404 that, if chained together, allow for arbitrary code execution from within the multiplayer mode. JSCEAL Campaign Undergoes a Shift — A Facebook ads campaign that's used to distribute a compiled V8 JavaScript (JSC) malware called JSCEAL has evolved into a more sophisticated form, with the attackers adopting a revamped command-and-control (C2) infrastructure, enhanced anti-analysis safeguards, and an updated script engine designed for increased stealth. "In contrast to the 1H 2025 campaign, which relied primarily on .com domains, the August 2025 campaign includes a broader variety of top-level domains such as .org, .link, .net, and others," Cato Networks said. "These domains are registered in bulk at regular intervals, suggesting an automated, scalable provisioning workflow." What's more, the updated infrastructure enforces stricter filtering and anti-analysis controls, blocking any HTTP request that does not present a PowerShell User-Agent. In the event a request includes the correct PowerShell User-Agent, the server responds with a fake PDF error rather than delivering the actual payload. It's only after the PDF has been returned that the C2 server delivers the next stage, including a modified version of the ZIP file containing the stealer malware. Third Defendant Pleads Guilty to Hacking Fantasy Sports and Betting Website — Nathan Austad, 21, of Farmington, Minnesota, has pleaded guilty in connection with a scheme to hack thousands of user accounts at an unnamed fantasy sports and betting website and sell access to those accounts with the goal of stealing hundreds of thousands of dollars from users. Austad and others launched a credential stuffing attack on the website in November 2022 and fully compromised approximately 60,000 user accounts. "In some instances, Austad and his co-conspirators were able to add a new payment method of their own on the account (i.e., to a newly added financial account belonging to the hacker) and then use it to withdraw all the existing funds in the victim account to themselves, thus stealing the funds in each affected Victim Account," the U.S. Justice Department said. "Using this method, Austad and others stole approximately $600,000 from approximately 1,600 victim accounts on the Betting Website." Access to the victim accounts was then sold on various websites that traffic in stolen accounts. Drop in Critical CVEs in 2025 — The number of critical vulnerabilities flagged in 2025 is at 3,753, down from 4,629 in 2023 and 4,283 in 2024, even as the total number of CVEs has increased to more than 40,000. According to VulnCheck, about 25.9% of the 43,002 CVEs published in 2025 have been enriched with a CVSS v4 score. "What this ultimately suggests is that CVSS v4 adoption is constrained not by lack of availability, but by limited participation from some of the largest and most influential CVE publishers and enrichers," it said. "Commonly cited reasons include resource constraints, required tooling changes, and a perception that CVSS v4 provides limited additional value while increasing scoring complexity and operational overhead." Amadey Uses Self-Hosted GitLab Instance to Distribute StealC — A new Amadey malware loader campaign has leveraged an exploited self-hosted GitLab instance ("gitlab.bzctoons[.]net") to deliver the StealC infostealer. "This analysis reveals how threat actors are hijacking abandoned, self-hosted GitLab servers to create a legitimate-looking payload distribution infrastructure," Trellix said. "The use of a long-standing domain with valid TLS certificates provides an effective evasion technique against traditional security controls." While the domain appears to belong to a small-scale organization hosting GitLab with multiple users, evidence suggests that either the user account or the entire infrastructure has been compromised. U.S. Dismantles E-Note Cryptocurrency Exchange — U.S. authorities seized the servers and infrastructure of the E-Note cryptocurrency exchange ("e-note.com," "e-note.ws," and "jabb.mn") for allegedly laundering more than $70 million from ransomware attacks and account takeover attacks since 2017. No arrests have been announced. In tandem, authorities have also indicted the site's operator, a 39-year-old Russian national named Mykhalio Petrovich Chudnovets, who is said to have started offering money laundering services to cybercriminals in 2010. Chudnovets has been charged with one count of conspiracy to launder monetary instruments, which carries a maximum penalty of 20 years in prison. The takedown fits into a broader law enforcement effort aimed at taking down services that allow bad actors to abuse the financial system and cash out the ill-gotten proceeds. 🎥 Cybersecurity Webinars How Zero Trust and AI Catch Attacks With No Files, No Binaries, and No Indicators — Cyber threats are evolving faster than ever, exploiting trusted tools and fileless techniques that evade traditional defenses. This webinar reveals how Zero Trust and AI-driven protection can uncover unseen attacks, secure developer environments, and redefine proactive cloud security—so you can stay ahead of attackers, not just react to them. Master Agentic AI Security: Learn to Detect, Audit, and Contain Rogue MCP Servers — AI tools like Copilot and Claude Code help developers move fast, but they can also create big security risks if not managed carefully. Many teams don’t know which AI servers (MCPs) are running, who built them, or what access they have. Some have already been hacked, turning trusted tools into backdoors. This webinar shows how to find hidden AI risks, stop shadow API key problems, and take control before your AI systems create a breach. 🔧 Cybersecurity Tools Tracecat — It is an open-source automation platform designed for security and IT teams that need flexible, scalable workflow orchestration. It combines simple YAML-based integration templates with a no-code interface for building workflows, along with built-in lookup tables and case management. Under the hood, workflows are orchestrated using Temporal to support reliability and scale, making Tracecat suitable for both local experimentation and production environments. Metis — It is an open-source, AI-powered security code review tool built by Arm’s Product Security Team. It uses large language models to understand code context and logic, helping engineers find subtle security issues that traditional tools often miss. Metis supports multiple languages through plugins, works with different LLM providers, and is designed to reduce review fatigue in large or complex codebases while improving secure coding practices. Disclaimer: These tools are for learning and research only. They haven’t been fully tested for security. If used the wrong way, they could cause harm. Check the code first, test only in safe places, and follow all rules and laws. Conclusion The past week made one point clear: the perimeter is gone, but accountability isn’t. Every device, app, and cloud service now plays a part in defense. Patching fast, verifying what’s running, and questioning defaults are no longer maintenance tasks — they’re survival skills. As threats grow more adaptive, resilience comes from awareness and speed, not fear. Keep visibility high, treat every update as risk reduction, and remember that most breaches start with something ordinary left unchecked.
thehackernews.comDec 22, 2025extracted
Loading 39 more…