Sign in

InfoSec

@infosec.skyfleet.blue
5.6K followers 506 following 71K posts

Relay Tracking News & Blogs about infosec, cybersec - source removal/addition suggestions welcome ! CVE : check out @cve.skyfleet.blue 🆘 @skyfleet.blue

PostsRepliesMedia
InfoSec @infosec.skyfleet.blue · 37m
Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS
cybersecuritynews.com
Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS
Cloudflare is building a certificate authority to make post-quantum website authentication practical without burdening TLS connections with oversized signatures. The company plans to issue conventional certificates alongside Merkle Tree Certificates, or MTCs, and is targeting early 2027 for admission to Chrome’s new Quantum-resistant Root Store; standard MTC issuance will be free. The initiative addresses a gap in web public key infrastructure. Browsers currently trust certificate authorities to validate domain control and bind a website’s identity to a public key, while Certificate Transparency logs expose issuance for auditing. That model works today, but Cloudflare estimates post-quantum signatures could increase CT storage requirements by 40 times; a typical TLS handshake already carries several signatures and keys. This matters because quantum-safe authentication must preserve both security and responsiveness across billions of websites, browsers, logs, monitors, and certificate renewals worldwide. Certificate Transparency Trust Ecosystem (Image Source: Cloudflare.com) MTCs redesign this process around an append-only Merkle tree. Instead of signing each certificate and subsequently submitting it to separate logs, the CA records certificate data in an issuance log and signs a checkpoint covering the tree’s state. A website then receives an inclusion proof, a sequence of hashes showing its certificate belongs to the signed tree. The concept changes the rule from “log what you issue” to “issue by logging,” making transparency part of issuance rather than a later attachment. Merkle Tree Certificate Logging (Image Source: Cloudflare.com) According to research published by Cloudflare , the company’s workflow will use ACME for requests and domain-control validation. Its ACME service will fork Boulder, the software behind Let’s Encrypt, which is developing MTC support. After validation, the CA adds the certificate data to its log, signs the updated checkpoint and submits it to a mirroring cosigner. That independent service checks append-only consistency, stores a copy, and helps prevent the CA from presenting conflicting log views. Chrome’s draft policy requires a cosignature from the issuing CA and another from a recognized mirror operated by a separate organization. Cloudflare intends to build its mirror with Azul, its open-source, Rust-based transparency-log software, while supporting the C2SP tlog-mirror protocol for interoperability. Only after obtaining the required cosignatures does the CA assemble the public key, inclusion proof, and signatures into a standalone MTC. Post Quantum MTC Architecture (Image Source: Cloudflare.com) The performance gain comes from landmark-relative certificates. Browsers can receive tree substructures, called landmarks, through an out-of-band update channel. During TLS negotiation, a server then sends only its certificate data and a lightweight proof connecting it to a trusted landmark, eliminating heavyweight post-quantum signatures from the handshake. Standalone MTCs remain necessary when a client is new, offline or lacks a current landmark. Cloudflare says a deployment with 50 percent of Chrome Beta 146 users served billions of MTCs for free-plan domains. Landmark handshakes transmitted one public key, one signature, and an inclusion proof smaller than 1 KB, producing a 9 percent median speed improvement over classical certificate chains. Importantly, the trial used classical signatures, and Cloudflare acknowledged that much of the measured gain came from removing the intermediate certificate. The design is promising but unfinished. MTC remains an active IETF PLANTS working-group Internet-Draft, not a finalized standard, and Cloudflare must still pass Chrome’s root-program review before browsers trust its certificates. Production deployment must also prove that independent monitors, multiple CAs, and diverse cosigners can process logs reliably at Internet scale. For defenders, CT monitoring will remain essential: organizations adopting post-quantum authentication should watch for unexpected legacy certificates that could enable a downgrade path. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 39m
CPython [CVE-2026-19445] Use-after-free of a server-side SSLContext when sni_callback switches contexts
seclists.org
oss-sec: CPython [CVE-2026-19445] Use-after-free of a server-side SSLContext when sni_callback switches contexts
Posted by Alan Coopersmith on Sep 30 -------- Forwarded Message -------- Subject: [Security-announce][CVE-2026-19445] Use-after-free of a server-side SSLContext when sni_callback switches contexts Date: Wed, 30 Sep 2026 16:10:08 +0000 From: Seth Larson <seth () python org> Reply-To: security-sig () python org To: security-announce () python org There is a CRITICAL severity vulnerability affecting CPython. A remote, unauthenticated TLS client can make a...
000
InfoSec @infosec.skyfleet.blue · 45m
Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux
cybersecuritynews.com
Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux
Google released a Chrome Stable update fixing 32 security vulnerabilities across Windows, macOS, and Linux, including one critical and multiple high-severity flaws in V8, ANGLE, GPU, WebGPU, Bluetooth, Passwords, and UI components. Chrome version 154.0.8037.92/.93 is being rolled out to Windows and Mac users, while Linux users will receive version 154.0.8037.92. Google said it will deliver the update to users over the coming days and weeks. The most serious flaw, CVE-2026-102331, is a critical ANGLE buffer overflow that can corrupt memory and potentially enable code execution in Chrome’s browser context. The update also fixes several high-severity vulnerabilities in Chrome’s V8 JavaScript engine. These include multiple type confusion issues, tracked as CVE-2026-102299, CVE-2026-102323, CVE-2026-102326, CVE-2026-102328, and CVE-2026-102321. Type confusion flaws occur when software incorrectly handles an object as a different type, which may lead to memory corruption or arbitrary code execution. Google also patched CVE-2026-102302, a high-severity buffer overflow in V8. Because V8 processes JavaScript from websites, attackers could use a malicious webpage to trigger a browser crash or exploit the vulnerability. Chrome Update With 32 Security Fixes Google also fixed several other memory-safety issues in GPU, WebGPU, WebGL, Dawn, Skia, Media, Bluetooth, Views, Passwords, FullScreen, and Picture-in-Picture components. Notable fixes include use-after-free flaws in Bluetooth, Views, Passwords, FullScreen, and Picture-in-Picture. A use-after-free vulnerability occurs when a program continues using a memory location after releasing it. Such flaws are frequently valuable to attackers because they can sometimes be chained with other weaknesses to gain code execution. Google also addressed CVE-2026-102329, a high-severity cross-site scripting issue in WebUI. Cross-site scripting flaws can allow attackers to inject malicious scripts into trusted browser pages or interfaces, potentially exposing sensitive information or manipulating browser settings. Other security fixes include improper privilege management in Mojo, missing authorization in CORS and Payments, incorrect authorization in WebView and SiteIsolation, and UI misrepresentation issues affecting the Omnibox, TabStrip, and SignIn components. Google has restricted access to technical bug details for several vulnerabilities until most Chrome users receive the update. This practice is intended to reduce the likelihood of exploitation before systems are patched. Users should update Chrome immediately by opening the browser menu, selecting Help, and choosing About Google Chrome. Chrome will automatically check for the latest release and prompt users to relaunch the browser after installation. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 1h
CPython [CVE-2026-19553] SSLContext.wrap_bio() missing validation of server_hostname parameter
seclists.org
oss-sec: CPython [CVE-2026-19553] SSLContext.wrap_bio() missing validation of server_hostname parameter
Posted by Alan Coopersmith on Sep 30 -------- Forwarded Message -------- Subject: [Security-announce][CVE-2026-19553] SSLContext.wrap_bio() missing validation of server_hostname parameter Date: Wed, 30 Sep 2026 16:08:09 +0000 From: Seth Larson <seth () python org> Reply-To: security-sig () python org To: security-announce () python org There is a HIGH severity vulnerability affecting CPython. `ssl.SSLContext.wrap_bio()` didn't require the...
000
InfoSec @infosec.skyfleet.blue · 1h
Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
cybersecuritynews.com
Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack
Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations. The campaign replaces an obvious malicious attachment with a conversation that looks like ordinary professional correspondence. The activity was recorded in at least 13 campaigns from January through August 2026, chiefly affecting organizations in the United States and United Kingdom. Government, diplomacy, research, public policy, journalism, and financial groups with Ukraine-related work were among the targets. Analysts at Field Effect noted that the operation reflects a wider shift by Star Blizzard, also known as ColdRiver or Callisto, from narrow spear-phishing toward larger initial-contact campaigns. The change lets operators identify people willing to engage before they send the harmful files. Field Effect said in a report shared with Cyber Security News (CSN) that compromised websites were used to create accounts for distributing phishing emails. The approach builds on the group’s history of adapting its lures, including malicious WhatsApp QR-code attacks aimed at high-interest targets. Russian Hackers Target 100+ Organizations The first message contains no attachment, malware, or exploit. Instead, attackers try to start a discussion, often exploiting the normal rhythm of invitations, policy exchanges, financial correspondence, research collaboration, or document sharing. A reply signals that the recipient may trust the sender and opens the door to the next stage. The follow-up message carries a password-protected RAR or ZIP archive, while its password appears as an image in the email. This arrangement can stop security products from inspecting the contents and makes the archive feel more credible because it arrives inside an existing exchange. Similar password-protected archive phishing tactics have been used to reduce email scanning visibility. Once opened, the archive may contain a VHDX virtual disk or a Windows shortcut, known as an LNK file, disguised as a PDF document. The files run scripts and legitimate Windows utilities to download further components from attacker-controlled infrastructure. This abuse of a document-like shortcut resembles earlier weaponized PDF and LNK attacks that hid harmful actions behind a decoy file. Beginning in April, RedFlick installers created scheduled tasks, gathered basic system details, enabled WebDAV access, and fetched material used to install the CosmicPulse backdoor. Scheduled tasks can give an attacker a reliable way to rerun code, while WebDAV is a Windows-supported method for accessing remote files. In July, the operators added another layer by placing a password-protected RAR archive inside a ZIP file. Its shortcut downloaded a PDF containing encoded data. PowerShell then extracted and ran that data to obtain an MSI installer, further separating the visible document from the malicious process. Detection and Response Priorities Microsoft observed RedFlick communicate with remote infrastructure, create scheduled tasks, and deploy CosmicPulse in at least one incident. That sequence can leave the attacker with persistent access to a Windows device, even after the original phishing email has disappeared from a user’s immediate view. Defenders should review email logs for encrypted RAR or ZIP archives that arrive after earlier attachment-free messages, especially when a sender says an attachment was omitted or supplies a password in the conversation. Teams should identify recipients who received, extracted, mounted, or opened the files, separating delivery from actual execution. Where operations allow it, encrypted archives that cannot be inspected should receive extra review before reaching endpoints. Security teams should also correlate archive extraction with VHDX mounting, LNK execution, MSI installers, PowerShell, WebDAV activity, scheduled-task creation, and unfamiliar external connections. If execution is suspected, responders should isolate the device, preserve the email thread and original archive, and inspect scheduled tasks and other persistence settings. Process and network records can reveal the infection path, while reviewing the user’s accounts, active sessions, mailbox rules, and recent messages may expose further targeting. The campaign shows why a clean-looking first email is not evidence of safety. Verifying unexpected requests through a known contact channel remains important, particularly for organizations handling Ukraine-related policy, research, diplomacy, journalism, or finance. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack appeared first on Cyber Security News .
111
InfoSec @infosec.skyfleet.blue · 1h
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
cybersecuritynews.com
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened.  The investigation does not stop at the verdict. SOCs still need to collect relevant evidence, document their findings, prepare the case for escalation, and determine whether the same infrastructure or techniques appear in other attacks.  That makes the workflow between detection, investigation, response, and threat hunting just as important as identifying the initial threat.  ANY.RUN has introduced several capabilities aimed at reducing the manual effort involved in these investigations. The updates combine deeper network and browser visibility, automated reporting, and threat intelligence correlation to help security teams move from initial detection to response and threat hunting more quickly.  Why Phishing Continues to Keep SOC Analysts Busy  The scale of phishing activity makes those investigation challenges harder to manage. Security teams are dealing with a steady stream of phishing-related alerts while attackers continue to introduce techniques that make individual incidents more difficult to analyze.  ANY.RUN’s H1 2026 Cyber Risk Report shows phishing exposure in 73.4% of investigations in the financial sector and 72.2% in manufacturing . Microsoft Incident Response has also found that 28% of the breaches it investigated began with phishing or social engineering , including newer techniques such as device-code phishing.  The financial impact is equally significant. The FBI recorded 191,561 phishing and spoofing complaints in 2025 , while Business Email Compromise generated $3.05 billion in reported U.S. losses .  For SOC analysts, the result is a combination of high investigation volume and increasingly complex attack chains. A single suspicious URL can require network analysis, browser inspection, reporting, and threat intelligence research before the case is ready to close or escalate.  The goal is to reduce the manual work between those stages without losing the evidence and context analysts need to make decisions.   94% of users report faster threat triage with ANY.RUN. Give your SOC the visibility to move from phishing alerts to action faster.  Improve SOC Triage 3 Steps to Strengthen Phishing Detection, Response, and Threat Defense  To see how these steps work in practice, let’s follow a phishing campaign that uses the following attack chain:  Cloudflare CAPTCHA → Phishing Document Lure → Device Code Phishing   The campaign involves EvilTokens , a phishing-as-a-service platform that abuses Microsoft’s legitimate device-code authentication flow to steal session tokens and gain access to accounts.  The technique creates several challenges for SOC analysts. It can combine CAPTCHA gates, redirects, legitimate cloud services, and dynamically generated phishing pages, meaning the activity visible at the initial URL may not reveal what happens later in the attack.  For this walkthrough, the investigation starts with the suspicious phishing activity and follows it through three stages: triage the attack, prepare the findings for response, and pivot into threat intelligence to identify related activity .  The complete attack is captured in an ANY.RUN sandbox session , allowing the investigation to follow the execution chain and examine the network and browser activity generated during the attack.  ANY.RUN Sandbox reveals the complete EvilTokens attack chain in under a minute   With the attack established, here is how the investigation can progress from the initial alert to broader threat intelligence.  Step 1: Accelerate Phishing Triage With Network and Browser Visibility  The first task is to establish what the suspicious URL actually does.  In modern phishing campaigns, important evidence can be hidden behind HTTPS encryption, redirects, CAPTCHA challenges, and browser-side scripts. Looking only at the original URL may leave an analyst without enough context to make a confident decision.  In the EvilTokens analysis, the suspicious URL is opened in ANY.RUN’s Interactive Sandbox . As the attack unfolds, the Network section records the web requests generated by the browser, including traffic that was originally encrypted over HTTPS.  Analysts can inspect individual request and response pairs through the Content view and identify suspicious resources involved in the attack.  One observed request is:  GET hxxps[://]preponacrea[.]com/est/js/main[.]js  Suspicious activity revealed in ANY.RUN Sandbox   SSL Decryption without MITM becomes useful here. The capability extracts encryption keys directly from process memory, allowing HTTPS traffic to be inspected without deploying a separate MITM proxy or replacing certificates.  But the network traffic is only part of the investigation. The In-Browser Data Inspection capability provides another view of the attack by allowing analysts to examine browser activity, including HTTP requests, DOM changes, iframes, screenshots, and redirects.  In-browser inspection reveals the phishing page’s full attack activity   For the EvilTokens campaign, this helps reveal how the browser moves through the phishing flow and what changes as the malicious page loads.  Together, the two capabilities give analysts visibility across both sides of the investigation: what the browser communicates with and what happens inside the browser itself .  That can reduce the need to manually piece together PCAP data, web logs, screenshots, and redirect chains before reaching a verdict. Tier 1 analysts can validate suspicious URLs faster and determine whether a case can be resolved or needs to be escalated.   95% of SOC teams speed up threat investigations with ANY.RUN. Move from phishing alerts to actionable response faster.  Explore ANY.RUN   Step 2: Turn the Investigation into a Response-Ready Case  Once the activity has been confirmed as malicious, the next challenge is communicating the findings.  The analyst needs to explain what happened, why the activity is malicious, which indicators are relevant, and what the next team should do. Without that context, Tier 2 or incident response may have to return to the original investigation and reconstruct the evidence before taking action.  The EvilTokens analysis can be turned into a structured Tier 1 report, bringing the key findings together in one place. The report includes the analysis verdict, relevant threat and campaign tags, key IOCs, technical events, an AI Summary, and AI Recommendations.   View the Tier 1 report for this analysis.   Tier 1 report summarizing the EvilTokens phishing attack   The AI Summary provides a condensed explanation of what happened during the session, while the recommendations give the responding team potential next actions to consider.  AI-generated summary of the EvilTokens phishing attack   For an analyst, this means the investigation does not have to end as a collection of raw sandbox findings. The evidence can be packaged into a format that another analyst can quickly understand and act on. That becomes particularly useful when a case moves from Tier 1 to Tier 2, incident response, or an MSSP customer.  Key IOCs identified for attack detection and threat hunting   The broader benefit is reducing the amount of time analysts spend translating technical findings into another incident summary and giving the next responder the context needed to continue the investigation.   Step 3: Pivot From EvilTokens IOCs to Related Threat Activity  The original phishing case can also provide a starting point for a wider investigation.  Attackers can rotate domains, IP addresses, and other infrastructure, so closing one malicious URL does not necessarily establish whether related activity exists elsewhere.  In the EvilTokens analysis, the observed HTTP endpoints provide useful behavioral indicators for further investigation:  /api/device/start  /api/device/status/  Analysts can take these patterns into ANY.RUN Threat Intelligence Lookup (TI Lookup) and search for other analyses where the same behavior has appeared.  See the EvilTokens query in TI Lookup   The new Connections view adds context by showing relationships between network artifacts such as URLs, domains, IP addresses, and other indicators. This allows analysts to move beyond checking individual IOCs and instead investigate how different pieces of infrastructure may be connected.  Connections view reveals related EvilTokens infrastructure in ANY.RUN’s TI Lookup   That distinction is important during threat hunting. An IP associated with a malicious analysis may belong to shared cloud or CDN infrastructure and therefore may not be an appropriate blocking candidate. Relationship context and filtering can help analysts separate potentially useful indicators from infrastructure that is widely shared.  The results can then support retrohunting, SIEM and NDR investigations, detection engineering, and blocking decisions.   Threat Intelligence Lookup also provides additional context around the wider threat activity, including geography and targeted industries, giving analysts more information to determine whether related activity is relevant to their environment.  ANY.RUN’s TI Lookup provides visibility into the wider threat landscape   What These Steps Mean for Phishing Response  Following the EvilTokens campaign through the three stages shows how a single phishing investigation can deliver more than a malicious verdict. The same evidence can continue to support the investigation as the case moves from triage to response and threat hunting.  For SOC analysts, the workflow provides:  Faster phishing triage: Encrypted traffic and browser activity can be examined together, giving analysts more context to validate suspicious URLs and understand the attack chain.  Clearer incident response: Investigation findings can be consolidated into a structured report with the verdict, IOCs, technical evidence, AI-generated summary, and recommendations for the next responder.  Broader threat visibility: Observed IOCs and attack patterns can be used to search for related activity and uncover connections between domains, URLs, IPs, and other infrastructure.  The result is a more continuous path from phishing detection to response and proactive defense, with less need for analysts to rebuild investigation context at each stage.   30% fewer Tier 1-to-Tier 2 escalations. Give analysts the context they need to investigate phishing faster.  Power Up Your SOC   The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster  appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 1h
PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries
cybersecuritynews.com
PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries
PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single obvious source. Instead, it spreads activity across thousands of addresses while repeatedly presenting fabricated phone and browser identities. The operation exposes weaknesses in simple IP-based defenses. Websites facing this traffic may see requests apparently arriving from dozens of countries, making location blocks and one-off address bans far less useful. The network was observed during a two-week period, although its infrastructure may have existed earlier. CrowdSec analysts identified PaperPhone after collecting bot signals following an August 31 detection update. Their September 29 report detailed the findings. CrowdSec said in a report shared with Cyber Security News (CSN) that the activity involved 75,000 IP addresses across 230 IP blocks and 43 countries. The report describes large-scale scraping, not a confirmed malware infection or data breach. Its findings build on the distinction explained in browser fingerprinting testing guidance , where browser characteristics reveal differences between automated environments and real devices. CrowdSec did not identify specific victims, stolen datasets, or financial losses. PaperPhone Headless Browser Network The apparent global footprint does not reflect worldwide users or devices. Researchers found that request peaks from distant countries moved together despite major time-zone gaps. Traffic attributed to Japan and the United States rose at closely related times, as did traffic presented as coming from Australia and Canada. That timing suggests central coordination, not independent browsing. The 230 blocks were mostly /24 ranges across 80 networks. Many were already recognized as data-center infrastructure, rather than residential proxies. Unlike the SystemBC proxy botnet operation , this investigation does not establish that servers were compromised. Address ownership and geolocation records also raised questions. A range could have registration, management, and claimed location details that point to different regions. Adjacent ranges were presented as being in cities from Brussels to Bangkok, Tokyo, and Paris, creating an artificial geographic picture. More than 20% of the observed cluster used M247 as its transit provider, despite none of the listed blocks belonging to that provider. Many blocks were used to their full capacity during scraping. Defenders should assess address-range behavior rather than treat every IP as unrelated. This transit relationship does not establish operator attribution. Researchers also observed addresses rotating after repeated challenge failures led to bans. This behavior helps explain why the number of detected addresses grew over time: both expanding telemetry and address cycling affected the picture. The earliest sightings therefore mark increased visibility, not necessarily the beginning of the operation. Fabricated Mobile Identities PaperPhone cycled through 13 claimed device identities, including five Android devices and seven iOS variants. Yet every observed bot reported the same 375×812 viewport. That size matches an iPhone 10 or 11 display area, not the varied handsets the network claimed to represent. The browsers also exposed Google SwiftShader through the WebGL renderer field, a software graphics renderer generally associated with systems lacking hardware acceleration. That is difficult to reconcile with the recent Android devices named in the traffic, including Pixel 9 and Samsung Galaxy S25 Ultra models, or with claimed iOS 14 and iOS 15 sessions. These contradictions show why country, user-agent, or IP reputation alone cannot establish legitimacy. Organizations should correlate request volume, address rotation, browser viewport, graphics behavior, device claims, and challenge failures. The importance of these signals also appears in macOS browser fingerprinting evasions , where attackers inspect visitors to hide malicious content. SwiftShader uses the processor to draw graphics rather than a dedicated graphics chip. CrowdSec interpreted the combination as evidence of Chrome-based automation without hardware acceleration, rather than genuine sessions from the phones advertised in the browser identities. The findings underline the limits of geographic blocking and individual address bans. Looking at request timing alongside browser characteristics provides a fuller picture than location labels alone. For this cluster, synchronized activity, identical display dimensions, software rendering, and concentrated address ownership exposed the automation beneath its supposedly diverse mobile visitors. Indicators of compromise (IoCs):- Type Indicator Description IP range 103.216.1.0/24 PaperPhone-associated range illustrating registration inconsistencies: APNIC origin, RIPE registration, Lithuanian registrant, and a claimed United States location. IP range 62.105.200.0/22 Range listed in the investigation with a claimed location of Brussels, Belgium. IP range 62.105.204.0/23 Range listed in the investigation with a claimed location of Bangkok, Thailand. IP range 62.105.208.0/23 Range listed in the investigation with a claimed location of Tokyo, Japan. IP range 62.105.210.0/23 Range listed in the investigation with a claimed location of Paris, France. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 1h
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
bleepingcomputer.com
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
000
InfoSec @infosec.skyfleet.blue · 1h
CVE-2026-80490: Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified
seclists.org
oss-sec: CVE-2026-80490: Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified
Posted by Robert Rothenberg on Sep 30 ======================================================================== CVE-2026-80490                                       CPAN Security Group ========================================================================         CVE ID:  CVE-2026-80490   Distribution:  Algorithm-AhoCorasick-XS       Versions:  through 0.04       MetaCPAN: https://metacpan.org/dist/Algorithm-AhoCorasick-XS       VCS Repo:...
000
InfoSec @infosec.skyfleet.blue · 1h
September 30, 2026
buttondown.com
September 30, 2026
September 30, 2026 Trial of live facial recognition in London stations leads to a false positive and no arrests Trial of live facial recognition in London...
000
InfoSec @infosec.skyfleet.blue · 2h
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
thehackernews.com
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting CVE-2026-76504 to access Cisco SD-WAN Manager APIs as admin without credentials; fixed releases are available.
032
InfoSec @infosec.skyfleet.blue · 2h
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
darkreading.com
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
010
InfoSec @infosec.skyfleet.blue · 2h
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
cybersecuritynews.com
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in September 2025, while later operations targeted additional programming ecosystems and security tools. Once attackers obtain working credentials, they can access cloud storage, inspect infrastructure, steal data, or establish lasting access. Qualys researchers noted this recurring pattern in their September 28 analysis. Qualys said in a report shared with Cyber Security News (CSN) that developer environments and cloud infrastructure must be treated as one connected attack surface, not separate security problems. Developer machines often hold cloud access keys, repository tokens, publishing credentials, and private keys. As attacks on SAP packages illustrate, stealing those secrets can expose systems far beyond the original software project, even when the compromised application never reaches production. Supply Chain Attacks Turn Developer Machines The decisive step happens during installation. Package managers can run scripts automatically, giving attackers access to the same files, environment variables, and credentials available to the developer or build job. Normal application protections may not engage before the theft has already occurred. Shai-Hulud initially searched infected environments for cloud credentials and uploaded stolen information to public GitHub repositories created under victims’ accounts. A November variant added backdoor functions and destructive behavior when credential theft failed, increasing the consequences of a compromised dependency. By May 2026, Mini Shai-Hulud was using scripts that execute before installation completes. Qualys reported that the May 19 wave compromised 639 package versions across 323 packages. Coverage of the Mini Shai-Hulud package compromise shows how infections spread through dependent libraries used in cloud development workflows. Cancelling installation after that script starts does not necessarily prevent exposure. The payload can already have collected repository tokens, cloud keys, and infrastructure secrets, leaving defenders with a credential compromise rather than merely an unwanted package. The Access Nexus (Source – Qualys) Other campaigns altered the build environment itself. BufferZoneCorp distributed malicious Ruby gems and Go modules disguised as developer utilities. These collected secrets, weakened package verification, intercepted commands, and sometimes added an attacker key to preserve remote access. TeamPCP also compromised trusted scanning tools and libraries. The European Commission cloud breach demonstrates the wider impact of stolen cloud credentials, with attackers moving from a poisoned development tool to unauthorized access and data theft. Between April 21 and 23, 2026, related attacks struck npm, PyPI, and Docker Hub within 48 hours. In another May campaign, 14 packages impersonating search libraries stole cloud and pipeline secrets. Attackers then used publishing tokens to infect more packages, turning one compromised developer account into a distribution channel for potentially widespread further credential theft. Containing Credential Theft And Exposure Removing a malicious package is only the beginning of recovery. Qualys recommends identifying every credential the affected machine or build system could access, revoking or rotating exposed secrets, and reviewing cloud activity throughout the period of exposure. Teams should reduce installation risks by approving dependencies, pinning versions through lockfiles, and checking that builds preserve those files. Where workflows permit, disable automatic installation scripts and allow only scripts that have been reviewed and are genuinely required. Build jobs should carry only the permissions needed for their work. A job that compiles software should not also hold deployment authority. Short lived credentials reduce reliance on permanent keys, while tighter cloud policies can prevent unauthorized administrator creation or disabled logging. Cloud audit records should be protected against modification and monitored for unusual activity. Investigators should examine unexpected access changes, newly created resources, and suspicious storage access. These checks help establish what attackers actually did after obtaining legitimate credentials. Finally, restrict access to cloud metadata services when build systems do not need them. Require AWS IMDSv2, prefer federated identities or managed identities where supported, and keep permissions narrow. Developer security and cloud response must follow the entire attack path. Indicators of compromise (IoCs):- Type Indicator Description Domain webhook.site Legitimate webhook service identified as an exfiltration channel. Its presence alone does not establish compromise. IP address 169.254.169.254 Legitimate cloud metadata endpoint targeted for credential harvesting, not an attacker IP. Restrict access where unnecessary. File path ~/.aws/credentials AWS credential storage location targeted for harvesting, not a malicious file. File path ~/.kube/config Kubernetes configuration location containing access information potentially exposed to malware. File name .npmrc npm configuration file targeted for credentials; also referenced for installation script controls. File name .netrc Authentication file identified as a credential harvesting target. File path ~/.ssh/authorized_keys Persistence location where a malicious Go module appended an attacker SSH public key. Executable name go Legitimate command impersonated by malicious wrappers to intercept future build commands. GitHub account BufferZoneCorp Account used to publish malicious Ruby gems and Go modules impersonating developer utilities. Package name @ctrl/tinycolor Legitimate npm package compromised during the original Shai-Hulud campaign; not every version is malicious. Package scope @antv npm ecosystem affected by the May 19 Mini Shai-Hulud wave. The source reports 639 compromised versions across 323 packages. Package name echarts-for-react Downstream package affected by the Mini Shai-Hulud campaign; the source provides no affected version numbers. Package name @bitwarden/cli Legitimate package name associated with a trojaned release in the April campaign. Environment variable GITHUB_TOKEN Repository credential targeted by Mini Shai-Hulud; a harvesting target, not a standalone compromise indicator. Environment variable AWS_ACCESS_KEY_ID AWS credential identifier targeted by the payload. Environment variable AWS_SECRET_ACCESS_KEY AWS secret access key targeted by the payload. Environment variable KUBECONFIG Kubernetes configuration reference targeted for infrastructure access information. Environment variable VAULT_TOKEN HashiCorp Vault authentication token targeted for theft. Environment variable GOPROXY Go module proxy setting redirected by malicious modules to alter dependency retrieval. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 2h
Cisco warns of new SD-WAN zero-day exploited in attacks
bleepingcomputer.com
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
000
InfoSec @infosec.skyfleet.blue · 3h
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
cybersecuritynews.com
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the links reach pages that imitate document portals, Adobe downloads, Zoom installation pages, or collaboration services. Microsoft analysts identified the activity in July 2026 across organizations in several industries. The operation delivers a real, digitally signed MSP360 Remote Monitoring and Management installer, but disguises it with names designed to look safe. Microsoft said in a report shared with Cyber Security News (CSN) that it has not tied the campaign to a named group. The finding shows why trusted administration tools can be just as dangerous as traditional malware when an attacker controls their installation. Hackers Disguise Remote Access Tools as Zoom and PDF Installers The initial file is MSP360 RMM version 2.5.0.67, presented as a meeting app, PDF utility, invitation, or business document. The disguises exploit the same misplaced trust as signed workplace application lures that abuse familiar names to lower suspicion. After a victim runs the file and approves the Windows administrator prompt, it installs MSP360 services and adds automatic startup entries. It also creates a firewall rule allowing inbound UDP traffic to the RMM agent on port 48678, giving the software the access it needs to communicate. The attackers did not exploit a flaw in the remote-control programs. Instead, they used legitimate tools as intended, except the remote session belonged to them. That distinction can make the intrusion blend into normal technical-support activity and complicate quick detection. Not every attempt succeeded. Where users denied or abandoned the administrator approval prompt, installation stopped before the remote-management components were fully deployed. Attack chain (Source – Microsoft) Microsoft also saw separate July activity using another legitimate deployment agent to install ScreenConnect, showing that the approach was not limited to MSP360. The delivery infrastructure changes frequently. Links have sent users to attacker-controlled sites, compromised websites, and cloud-hosted locations on Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. This rotating approach echoes weaponized PDF RMM attacks , where a convincing document is only the first step toward a remote-access installation. Second Channel Extends Control Once MSP360 is active, its agent launches PowerShell to download an installation package and silently install a ConnectWise ScreenConnect client. That creates a second independent route into the computer, so removing one remote tool may not immediately cut off the intruder. The ScreenConnect service then transfers and runs follow-on utilities from temporary folders in the user’s Documents or OneDrive Documents directory. Researchers observed tools associated with password theft, browser-data collection, hiding windows or cursors, and launching further files, raising the risk of account compromise and wider network access. This layered setup gives operators persistence, file transfer capability, and remote command execution while using software many IT teams recognize. It reflects the same operational problem seen in the SMOKE#SCREEN remote-control campaign , where fake updates turn approved-style support software into an attacker foothold. Organizations should maintain an inventory of approved remote-management applications and block unapproved instances, including by publisher certificate where appropriate. They should require multi-factor authentication for sanctioned tools, keep cloud-based endpoint protection enabled, and investigate any unexpected RMM installation before it becomes a durable connection. Security teams should also hunt for the listed installer hash, new MSP360 or ScreenConnect services, PowerShell started by the remote agent, and silent Windows Installer activity. If an unauthorized deployment is found, passwords for accounts used to install the services should be reset, with deeper investigation when system-level credentials were involved. Microsoft also recommends blocking or auditing process creation through PsExec and Windows Management Instrumentation, while checking for compatibility problems on some servers. These controls target ways attackers can move between systems after gaining their first foothold. Email filters reduce chances that users reach deceptive download pages. Indicators of Compromise (IoCs):- Type Indicator Description SHA-256 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc Legitimate MSP360 RMM v2.5.0.67 installer distributed under deceptive filenames; the sample was signed with a certificate that has since been revoked SHA-1 f34330d4c6e0aa978dc3af40360c14b31ad51127 MSP360 RMM installer hash observed in the campaign SHA-256 f094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97 857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de3 6a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e 4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26 Legitimate MSP360 RMM Agent Service samples observed during the campaign Domain adswre[.]cfd trews[.]cfd swedcorry[.]stefneyv[.]com ojsuyw[.]niyari[.]org bunstar[.]harej[.]si adsaw[.]cfd sdfghj[.]rd-team[.]ru Domains contacted by ScreenConnect clients during observed malicious sessions SHA-256 ceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b0 02f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550 499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a d49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc 67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f55 6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc dd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b64 40f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b1 3ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096 374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187 bc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6c c2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead208 5bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b 19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1 d232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126db d3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53ef e31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e3 1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8 77fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27a fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 06ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426b a93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657 529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63 ccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88 a03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b Utilities transferred or executed through ScreenConnect sessions during post-compromise activity File name VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe Observed deceptive MSP360 installer filenames File name ClientSetup.msi WindVerify.exe WindowsUpdate.exe WindowsSecurity_PIN.exe WindowsSecurity_Password.exe WindowsPassKey.exe SCHider.exe PIN.exe phonepc.exe DefenderDT.exe DefenderControl.exe phonelinkupdate.exe PhoneLinkPrompt.exe Passwords.EXE OpenCamera.exe open_phone_link.exe MouseHiderGUI.exe HideUL.exe HideMouseApp.dll HideMouse.exe HideFromControlPanel.exe HideCursor.exe BannerHider.exe WebBrowserBookmarksView.exe WebBrowserPassView.exe ScreenConnect installer and utilities observed during post-compromise activity Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .
020
InfoSec @infosec.skyfleet.blue · 3h
AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub
cybersecuritynews.com
AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub
AI coding agents exposed more than 13,000 internal screenshots from over 300 organizations by publishing them in publicly accessible GitHub repositories, according to “PixelLeak” research from Glow Labs. The material spanned more than 900 repositories across cloud, healthcare, fintech, government and AI, including several Fortune 500 companies. The exposures began with a routine development workflow. Engineers asked coding agents to make interface changes, capture before-and-after images and add them to pull requests for review. Glow said agents operating through text-based command-line environments could not use the image-upload process available through GitHub’s browser interface, prompting them to find another route. Their solution was frequently to create or use an adjacent public repository and link its images from the private pull request. That workaround transformed routine proof-of-work into a serious data exposure. Researchers discovered customer records, utility billing information, credentials, personally identifiable information, internal dashboards, unreleased product features and financial interfaces. At one large manufacturer, an agent placed screenshots from an internal billing-screen fix in a public repository under the developer’s personal account. Because the assets sat outside the corporate GitHub organization, its security team did not discover them before Glow’s notification. A small open-source utility called gitshot contributed to exposures at roughly one-third of the affected organizations. The tool can place review images in a public “gitshot-images” repository as GitHub release assets under a _gitshot tag. AI Coding Agents Leak Internal Screenshots Glow identified more than 100 public accounts leaking development material through this pattern, including accounts associated with an AI model company, a payments provider and a financial firm whose images showed treasury, settlement and money-movement interfaces. Unsafe agent behavior also spread between systems. At one software vendor, multiple agents adopted public screenshot hosting as a reusable skill. Within a week, more than a dozen agents were applying it to development tickets, eventually uploading over 1,000 screenshots and recordings with descriptions of features still weeks or months from release. Visibility gaps hindered detection. Glow reported that 93% of cases involved repositories created under employee usernames, outside company-controlled organizations. Conventional secret scanners may miss sensitive information embedded in pixels, while release assets can leave a repository’s normal file listing appearing empty. Glow began notifying identified organizations on September 9, 2026, but cautioned that others may remain affected. Security teams should map everyone with access to private repositories, including former employees, and inspect associated public repositories, gists, releases and _gitshot tags. Exposed assets should be removed everywhere, while visible passwords, tokens and other credentials must be rotated. Organizations should inventory “shadow AI,” remove unapproved developer utilities and audit shared agent instructions capable of propagating unsafe workarounds. Pre-execution controls can block or require approval before an agent creates a public repository, pushes to a personal account, publishes a gist or changes repository visibility. Blanket auto-approval should be disabled so developers can inspect the intended destination before information leaves an endpoint. GitHub now offers a safer native path. GitHub CLI version 2.99.0 introduced a repeatable --attach flag that supports authenticated image and video uploads to issues, pull requests and comments when users possess repository write access. Organizations should update their GitHub CLI installations , test agent compatibility and prohibit public fallback hosting so review evidence inherits private-repository access controls. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post AI Coding Agents Leak 13,000+ Internal Screenshots From 300+ Companies on GitHub appeared first on Cyber Security News .
022
InfoSec @infosec.skyfleet.blue · 3h
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
bleepingcomputer.com
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]
000
InfoSec @infosec.skyfleet.blue · 3h
Microsoft to block Entra ID script injection attacks starting October
bleepingcomputer.com
Microsoft to block Entra ID script injection attacks starting October
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]
000
InfoSec @infosec.skyfleet.blue · 4h
OpenAI reportedly ignored security warnings but Trump backs AI self-policing
metacurity.com
OpenAI reportedly ignored security warnings but Trump backs AI self-policing
Employee accounts of ignored warnings and a lawsuit over autonomous hacking sharpen questions about accountability as the White House embraces voluntary safeguards and AI labs pursue their own standards body.
000
InfoSec @infosec.skyfleet.blue · 4h
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
cybersecuritynews.com
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through the card or ID lookup field, installed an in-memory loader and web shell, used that foothold to deploy an AdaptixC2 implant hidden inside a modified Microsoft Copilot binary. eSentire said in a report shared with Cyber Security News (CSN) that its analysts detected the intrusion on August 31, 2026, at an education-sector customer. Its analysts found that the attackers moved from the print server to a domain controller in less than two days. The case underlines the danger of leaving management applications exposed online. It follows reports that the PaperCut flaws were actively exploited, with defenders warned to restrict public access and watch for suspicious activity from the service. Hackers Turned a PaperCut Print Server The initial compromise relied on CVE-2026-81578 and CVE-2026-82078, a pair of vulnerabilities that can be chained to alter settings without authentication and run malicious Java bytecode in the PaperCut server’s security context. Earlier coverage of the actively exploited PaperCut flaws explains why internet-facing application servers need urgent attention. The first-stage loader was designed for broad compatibility across different Tomcat releases. It rebuilt payload fragments in memory, started the next stage, and removed its own files. The web shell then accepted instructions through a custom HTTP header, ran commands, read configuration values, and deleted traces from logs and the internal application database. Attack chain overview (Source – eSentire) That cleanup mattered. The web shell also placed itself early in the server’s request-processing chain and blocked unrelated attempts to use the same weakness. In effect, the attackers tried to preserve exclusive control while making the original break-in harder to investigate. The modified binary established contact with remote attacker infrastructure, then remained quiet for roughly a day. Operators then returned for hands-on activity, illustrating how attackers use open-source command-and-control attack frameworks to expand access after breaching a vulnerable server. Credential Theft Once active, the attackers surveyed hosts, networks, domain trusts, and administrator groups. They identified a process running under a domain-privileged service account, copied its access token, and relaunched the implant with that account’s rights. No stolen administrator password was needed to begin the move toward the domain controller. Using those privileges, the group copied its payload to the domain controller through an administrative file share. It then temporarily changed the Windows PlugPlay service configuration to start the payload, stopped the service after launch, and restored the legitimate service path. That sequence allowed execution while reducing evidence of the change. On the domain controller, the attackers dumped credentials from memory and the registry. They enabled Windows Restricted Admin mode, used a recovered NTLM hash to sign in over Remote Desktop Protocol, and created a copy of the Active Directory database. That database can contain password hashes for every domain account, creating a serious risk of further pass-the-hash movement. The attackers packaged the database and supporting registry data into an archive for exfiltration. Their customized implant used encrypted settings and scrambled program logic to hinder analysis. Public sandboxes also failed to run the modified binary when its legitimate supporting library was missing. Administrators should update PaperCut MF or NG to the latest release and allow only trusted IP addresses to reach its application servers. They should monitor child processes of the PaperCut service, missing or unexpectedly shortened server logs, and unusual post-exploitation behavior. Recent reporting on emergency PaperCut security updates also highlights the need to apply vendor fixes without delay. Security teams should review the vendor advisory’s indicators, look for the log errors identified by the researchers, and investigate unexpected changes to service configurations. Researchers also recommend reducing service-account permissions and maintaining endpoint monitoring. eSentire isolated the affected host and helped the customer with remediation following the intrusion. Indicators of Compromise (IoCs):- Type Indicator Description URL hxxps://taibeianmo.oss-cn-hongkong.aliyuncs[.]com/mscopilot.exe Download URL for AdaptixC2 implant URL hxxps://uneedcargo.oss-accelerate.aliyuncs[.]com/65722.txt Additional OSINT-discovered download URL for the same AdaptixC2 implant IPv4 47.79.64[.]225 Download IP for AdaptixC2 implant IPv4 156.227.0[.]13 AdaptixC2 command-and-control server IP File hash d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222 Trojanized Microsoft Copilot with AdaptixC2 implant File hash cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c Trojanized wa_3rd_party_host_64.exe, named PulseSecure.exe, with AdaptixC2 implant File hash bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58 Java bytecode stage 1 loader, jakarta variant File hash 33d0a8294d2520608dbc4901c3ebd525aaeb7b8eceba9d140f62efa419a8c55a Java bytecode stage 1 loader, javax variant File hash a8ff38e5f21a5202e1ce33e62b9ddde4ec4faffabd52a4a146cff18c877fe7ca Decompiled stage 1 loader, jakarta variant File hash f893ab902cf0ad1a62cdfe04c58ba7560db7a0f5153303af18bd549c6619a044 Decompiled stage 1 loader, javax variant File hash 9c8760f8b973360701774bc56c7c97295eb42d49a02a281cbaadc32c973bd8b2 Java bytecode stage 2 shell, jakarta variant File hash d91c10536293d23bd3ebfc0f922e367303f455571556d83684170183dd6897f4 Java bytecode stage 2 shell, javax variant File hash 8673371d266d041dae20f64e0532d2bca65c3b09a6c0faf16a6546e6067bac2e Decompiled stage 2 shell, jakarta variant File hash 1a7541b30dcccd91e969f0e1586ba18fbf3a7d78f960654a5c1489108e516180 Decompiled stage 2 shell, javax variant Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 4h
Hackers Broke Into Microsoft 365 Through Forgotten Accounts Nobody Was Watching
cybersecuritynews.com
Hackers Broke Into Microsoft 365 Through Forgotten Accounts Nobody Was Watching
Hackers have breached Microsoft 365 environments by targeting accounts that were still active but unmonitored. An old password and missing sign-in protections gave intruders a route into email, files, and cloud applications. The campaign focused heavily on organisations in Chile, including a large retailer and financial institutions. Rather than repeatedly guessing passwords for one person, the operator tested likely default passwords across many accounts, a technique seen in similar password spraying attacks , then used successful logins to explore cloud services. Proofpoint analysts identified the activity as UNK_CondorFiltration, a campaign abusing TeamFiltration, a testing framework rather than a new malware strain. Proofpoint said in a report shared with Cyber Security News (CSN) as source material that the operation hit 5,714 accounts across 28 Microsoft 365 tenants and produced seven confirmed compromises. The numbers underline a narrow but serious weakness. None of the confirmed breaches involved personal employee accounts. Every affected identity was a functional or service account, the kind created to process payments, run ticketing, support point-of-sale systems, or perform other routine tasks without a person regularly logging in. Hackers Broke Into Microsoft 365 Through Forgotten Accounts Researchers found that the seven compromised accounts had no earlier legitimate sign-in activity in the available records. Six were breached within seven minutes, a pattern that points to shared or unchanged default passwords rather than individually stolen credentials. The accounts remained enabled, lacked clear ownership, and apparently had no multi-factor authentication, or MFA, to stop a valid password from being enough. One retailer accounted for 25,715 of the campaign’s 32,825 authentication events, or 78.3 percent. The August 13 to 16 wave peaked at about 1,560 targeted accounts on August 15, and all seven confirmed compromises occurred at the retailer on August 14 and 15. The pattern resembles a earlier TeamFiltration takeover campaign using the same framework against cloud identities. TeamFiltration can check whether accounts exist through the Teams API, test passwords at scale, and use cloud infrastructure to vary its source locations. Following a successful sign-in, it can collect email, Teams messages, and OneDrive or SharePoint data. That makes an overlooked operational account particularly useful. The findings point to practical safeguards. Organisations should inventory service accounts, assign an accountable owner, remove accounts that no longer serve a purpose, rotate any inherited credentials, and require MFA or a safer workload identity where possible. Teams should also review conditional-access rules and sign-in logs for broad failures across many accounts, as coverage of Microsoft 365 spraying attacks also explains. From Valid Login to Cloud Reconnaissance The activity did not always end with a password check. For most affected accounts, researchers observed access to Microsoft Office, OneDrive, and Teams from the same cloud-hosted infrastructure. That behavior is consistent with TeamFiltration’s automatic collection mode, though sign-in logs alone cannot prove that files or messages were removed. In one case, the attacker changed to a German VPN node within 90 seconds of the initial compromise. The operator unsuccessfully probed the corporate VPN, then opened Azure Portal, OfficeHome, and SharePoint Online. An MFA enrolment prompt during the Azure Portal visit indicated that the compromised account had not been configured for MFA. The SharePoint access could have supported document discovery, data theft, or an attempt to place a harmful file where a trusted user might later open it. A request for an access token through the SharePoint Online Web Client Extensibility application also suggested an effort to interact with Microsoft Graph or external application interfaces. Similar post-login abuse has appeared in reports on hidden cloud mailbox rules , which can help intruders quietly retain visibility into business email. Defenders should treat inactive accounts as an identity risk, not administrative clutter. Alerting on the distinctive user agent, password attempts from distributed cloud hosts, first-time sign-ins, and sudden access to sensitive apps can expose this type of intrusion early. Blocking legacy or unnecessary sign-in paths and testing MFA coverage on non-human accounts can close the gap that this campaign exploited. Indicators of compromise (IoCs):- Type Indicator Description User agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Teams/1.3.00.30866 Chrome/80.0.3987.165 Electron/8.5.1 Safari/537.36 Hardcoded TeamFiltration default user agent used to identify the activity. IP range 3.101.0.0/16 AWS EC2 infrastructure associated with password spraying. IP range 18.144.76.0/24 AWS EC2 infrastructure associated with password spraying. IP range 13.52.201.0/24 AWS EC2 infrastructure associated with password spraying. IP address 3.101.157.240 Source of the initial Microsoft Teams compromise in the documented case. IP address 149.88.104.19 German VPN node used for subsequent VPN probing and cloud application access. Provider domain amazon.com Legitimate provider domain associated with the AWS attack infrastructure, not a malicious domain by itself. Provider domain cdn77.com Provider attribution associated with the post-access IP, not a malicious domain by itself. Provider domain datacamp.co.uk Additional provider attribution for the post-access IP, not a malicious domain by itself. Redacted endpoint vpn.[redacted].cl/SAML20/SP Victim corporate VPN endpoint as printed in the source. Redaction prevents operational use. Redacted URL https://vpn.[redacted]/SAML20/SP Corporate VPN target application identifier recorded in telemetry. Preserved exactly as published. Application ID 1fec8e78-bce4-4aaf-ab1b-5451cc387264 Legitimate Microsoft Teams application accessed through all seven compromised accounts; useful for correlating suspicious activity. Application ID d3590ed6-52b3-4102-aeff-aad2292ab01c Legitimate Microsoft Office application accessed through all seven compromised accounts. Application ID ab9b8c07-8f02-4f72-87fa-80105867a763 Legitimate OneDrive SyncEngine application accessed through a subset of compromised accounts. Application ID c44b4083-3bb0-49c1-b47d-974e53cbdf3c Legitimate Azure Portal application involved in the documented post-compromise sequence. Application ID 4765445b-32c6-49b0-83e6-1d93765276ca Legitimate OfficeHome application accessed through one compromised account. Application ID 00000003-0000-0ff1-ce00-000000000000 Legitimate SharePoint Online application accessed during potential document reconnaissance. Application ID 08e18876-6177-487e-b8b5-cf950c1e598c Legitimate SharePoint Online Web Client Extensibility application involved in an access-token request. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Hackers Broke Into Microsoft 365 Through Forgotten Accounts Nobody Was Watching appeared first on Cyber Security News .
032
InfoSec @infosec.skyfleet.blue · 5h
TeamViewer urges users to patch severe flaws “as soon as possible”
bleepingcomputer.com
TeamViewer urges users to patch severe flaws “as soon as possible”
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
000
InfoSec @infosec.skyfleet.blue · 5h
Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
therecord.media
Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.
054
InfoSec @infosec.skyfleet.blue · 5h
Medela - 423,947 breached accounts
haveibeenpwned.com
Have I Been Pwned: Medela Data Breach
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact information, including names, physical addresses and phone numbers, with some records also containing associated support tickets.
000
InfoSec @infosec.skyfleet.blue · 5h
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
thehackernews.com
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Glow found over 13,000 internal images from 300+ organizations exposed in public GitHub repos during AI-assisted code reviews.
010
InfoSec @infosec.skyfleet.blue · 5h
FBI’s Operation Blackout Dismantles Scammers Operating Overseas Targeting Americans
cybersecuritynews.com
FBI’s Operation Blackout Dismantles Scammers Operating Overseas Targeting Americans
The FBI has dismantled overseas scam compounds accused of stealing Americans’ savings through cryptocurrency investment fraud , romance schemes, impersonation scams, and other cyber-enabled operations. Under Operation Blackout, authorities have seized or restrained roughly $17 billion, arrested hundreds of suspects and freed thousands of trafficked workers forced to conduct fraud from industrial-scale facilities in Southeast Asia, the Middle East and Africa. FBI Director Kash Patel described the sites as purpose-built “towns” and “cities” where criminal syndicates confine workers and direct them to contact targets through social media, phone calls, text messages and Telegram. Unlike conventional call centers, these compounds combine human trafficking, scripted social engineering, digital payment infrastructure, and organized money laundering, allowing operators to reach victims worldwide while remaining beyond US borders. They built entire scam cities overseas to steal Americans’ life savings. So we went to the source. Operation Blackout: ✓ Roughly $17 BILLION seized ✓ Hundreds arrested ✓ Thousands of trafficked workers freed ✓ 10,000+ Americans warned before losing their money ✓ $660… pic.twitter.com/NllcUWIcXn — FBI Director Kash Patel (@FBIDirectorKash) September 29, 2026 The fraud chain commonly begins with an unsolicited message or apparently accidental contact. Operators cultivate trust, sometimes through a fabricated romantic relationship, before steering victims toward counterfeit cryptocurrency platforms displaying manipulated profits. Once larger deposits arrive, operators block withdrawals, demand additional “taxes” or fees, and move stolen funds through wallets and laundering services. The Justice Department previously alleged that Cambodia’s Prince Group used forced-labor compounds for such schemes; US authorities took custody of approximately 127,271 Bitcoin valued at about $15 billion in the department’s largest forfeiture action. Operation Blackout attacks several layers of that ecosystem simultaneously. Investigators work with foreign law-enforcement partners to raid physical compounds, seize computers and storage media, trace cryptocurrency, interrupt communications and pursue organizers. During an August search of Cambodia’s roughly 200-acre O’Smach Resort compound, authorities searched 28 buildings and collected 113 hard drives, 15 computers and 35 boxes of evidence. In Madagascar, a Justice Department Scam Center Strike Force deployment supported local authorities in dismantling 13 Chinese-run scam centers and processing more than 3,200 electronic devices. The FBI is also intervening before payments become irreversible. Through Operation Level Up, its US-facing prevention component conducted with the Secret Service, investigators identify likely cryptocurrency-investment-fraud victims and contact them directly. Officials said 10,406 people had been warned, 77 percent of whom did not realize they were being deceived. Those interventions reportedly prevented an estimated $660 million in losses, while authorities seized or froze an additional $122 million in cryptocurrency. Digital disruption has accompanied the raids. The bureau reported seizing 584 scam websites and referring 7,670 fraudulent accounts to private-sector platforms for action. It also referred 99 endangered victims for suicide intervention, underscoring the severe psychological damage associated with life-changing financial losses. The figures are significant against the FBI’s 2025 data, which recorded 61,559 cryptocurrency-investment complaints and approximately $7.23 billion in reported losses; victims aged 60 and older accounted for about $2.76 billion. For potential victims, the immediate response remains critical: stop sending money, contact the financial institution, preserve messages, domains, phone numbers, wallet addresses and transaction hashes, and report the incident at IC3.gov. Because cryptocurrency transfers can cross borders rapidly, early reporting can help investigators trace funds, notify exchanges and identify connected wallets before proceeds are dispersed through global laundering networks. The FBI warns against paying supposed recovery companies, which often target victims again. Operation Blackout’s expansion into central and sub-Saharan Africa also signals that displacement is expected: shutting down one compound may redirect the network, but coordinated infrastructure seizures, financial tracing, and victim notification can make relocation costlier and expose the organizations behind the fraud. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post FBI’s Operation Blackout Dismantles Scammers Operating Overseas Targeting Americans appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 5h
CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
seclists.org
oss-sec: CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
Posted by Colm O hEigeartaigh on Sep 30 Severity: important Affected versions: - Apache WSS4J 4.0.0 before 4.0.2 - Apache WSS4J 3.0.0 before 3.0.6 - Apache WSS4J before 2.4.4 Description: An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the...
000
InfoSec @infosec.skyfleet.blue · 6h
CVE-2026-92899: Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
seclists.org
CVE-2026-92899: Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
Posted by Colm O hEigeartaigh on Sep 30 Severity: moderate Affected versions: - Apache WSS4J 4.0.0 before 4.0.2 - Apache WSS4J 3.0.0 before 3.0.6 - Apache WSS4J before 2.4.4 Description: Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an...
000
InfoSec @infosec.skyfleet.blue · 6h
Bitget hacked via zero-day in third-party security products
bleepingcomputer.com
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
010
InfoSec @infosec.skyfleet.blue · 6h
CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
seclists.org
CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
Posted by Colm O hEigeartaigh on Sep 30 Severity: moderate Affected versions: - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 4.0.0 before 4.0.2 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 3.0.0 before 3.0.6 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) before 2.4.4 Description: In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set....
000
InfoSec @infosec.skyfleet.blue · 6h
CVE-2026-89238: Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection
seclists.org
oss-sec: CVE-2026-89238: Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection
Posted by Colm O hEigeartaigh on Sep 30 Severity: important Affected versions: - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-dom) 4.0.0 before 4.0.2 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-dom) 3.0.0 before 3.0.6 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-dom) before 2.4.4 Description: WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and...
000
InfoSec @infosec.skyfleet.blue · 6h
Hackers Turn One Compromised Account Into Access to Azure DevOps and Kubernetes
cybersecuritynews.com
Hackers Turn One Compromised Account Into Access to Azure DevOps and Kubernetes
A single compromised account can open the door to an entire cloud estate. A recent investigation shows how an attacker used one compromised identity to move from password recovery into Azure DevOps, development pipelines, and Kubernetes resources. The incident did not rely on a software flaw or custom malware. Instead, the intruder abused trusted services that organizations use every day, turning ordinary access rights into a route toward source code, deployment settings, and infrastructure credentials. Microsoft analysts identified the activity as Storm-3068 and found that the actor took over an account through a self-service password reset. Microsoft said in a report shared with Cyber Security News (CSN) that registering its own authentication methods gave the attacker persistent access. The case illustrates why development systems have become attractive targets. Earlier attacks against Microsoft Entra ID accounts similarly abused legitimate cloud features, although they involved a different actor. Here, connected repositories, automation pipelines, and cloud resources amplified the impact of one compromised identity. Hackers Turn One Compromised Account Into Access After gaining control of the account, Storm-3068 used legitimate administrative tools and automated scripts to examine Azure DevOps projects, repositories, pipelines, and deployment environments. This discovery helped the intruder understand which systems were connected and where valuable credentials might be available. Azure DevOps was useful because it brought together software development and cloud operations. A separate Azure DevOps MCP flaw highlighted another way to misuse authorized access, but this intrusion instead exploited an account’s existing permissions to map trusted deployment paths and connected resources. The actor then created a malicious pipeline aimed at collecting Kubernetes credentials at scale. It deployed a kube agent and ran multiple jobs intended to collect cluster configuration files containing connection details and authentication information needed to access Kubernetes resources. Microsoft said the attacker deployed a pipeline authorized to access more than 50 resources and authenticate to services. Investigators later found that seven stolen cluster configuration files had been added to a repository, providing credentials needed to access targeted Kubernetes clusters. That sequence shows how a development platform can reveal more than source code. Repositories, service connections, and deployment settings can provide a roadmap into an organization’s broader environment, allowing an attacker to extend access through relationships already trusted by the business. Cloud Access Storm-3068 also altered pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility. Investigators said these changes were intended to create alternative remote-access paths and expose the Kubernetes API server for possible interaction with the clusters. Chisel commands established a reverse tunnel to an external IP address, although the supplied source did not disclose that address. Azure DevOps audit logs and Git version history helped investigators reconstruct the intrusion and identify the stolen credentials placed in the repository. Microsoft’s response team analyzed records across identity systems, development platforms, and cloud infrastructure to determine how far the attacker had moved. It worked with the affected organization through daily briefings, prioritized containment guidance, and recommendations intended to reduce opportunities for another compromise. DART also collaborated with Microsoft Threat Intelligence to place the activity in a broader threat context. That coordination helped refine the investigation and focus response efforts across affected environments as new details emerged. Organizations should monitor password-reset activity for repeated attempts or patterns involving multiple users. They should reduce privileged accounts’ exposure to self-service reset workflows and require phishing-resistant multifactor authentication, measures relevant to the separate password reset portal exposure reported earlier this month. Development teams should require approvals for code changes, enforce branch protection, and restrict direct commits to critical branches so updates follow established review processes. Pipeline permissions should also limit who can create, modify, or execute build and deployment workflows, reducing opportunities for unauthorized changes. Finally, least-privilege access should apply across identities, development platforms, and cloud resources. Regular reviews of identity, DevOps, and cloud controls can reduce the chance that one compromised account becomes a pathway into production environments through the organization’s own trusted connections. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Hackers Turn One Compromised Account Into Access to Azure DevOps and Kubernetes appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 7h
Security Teams Can Now Check for Claude Chats, Files and AI Agent Activity
cybersecuritynews.com
Security Teams Can Now Check for Claude Chats, Files and AI Agent Activity
The Claude Compliance API gives security teams visibility into employee and AI-agent activity, integrating Claude data with existing monitoring, DLP, identity, eDiscovery, SIEM, and security workflows. The change addresses a growing enterprise security challenge: generative AI tools are increasingly used for research, software development, document processing, and automated workflows, but they can also become a channel for sensitive-data exposure, risky prompt activity, unapproved connectors, and agent misuse. For Claude Enterprise customers, the API can provide access to conversation content, including chats, uploaded files, and projects. It can also collect session content from Claude Code and Cowork , including prompts, responses, tool-call content, skills, and artifacts captured as transcript text. In supported scenarios, it can also monitor Claude activity from Microsoft 365 add-ins, including Word, Excel, PowerPoint, and Outlook. This visibility lets defenders investigate whether sensitive information such as credentials, personally identifiable information, source code, financial data, or regulated content was shared with Claude. Security platforms can classify the data, apply policy rules, generate alerts, and send relevant events to a SIEM or case-management workflow. The Compliance API also records activity-feed events. These include user logins, administrative actions, and configuration changes for Claude Enterprise. Security Teams Can Monitor Claude Activity For Claude Platform customers, the activity feed can cover administrative and system events, such as workspace changes, member updates, API key creation, account-setting changes, file downloads, file creation, and skill changes. Conversation prompts and model responses are not available through the API for Claude Platform deployments. The monitoring expansion is particularly relevant for agentic AI. Organizations are adopting Claude Code, Cowork, model context protocol servers , connectors, plugins, and AI skills that can access internal tools and data. Such integrations create new identity, authorization, and software supply-chain risks. Security teams need to know which agents are active, what resources they can access, which MCP servers they invoke, and whether their activity remains within approved policy boundaries. Several vendors have announced API integrations. Security platforms including CrowdStrike, SentinelOne, Splunk, Elastic, Datadog, Microsoft Purview, Palo Alto Networks, Check Point, Cloudflare, Netskope, Zscaler, Proofpoint, Varonis, Wiz, and others can ingest or analyze Claude-related telemetry for detection, governance, auditing, and data-protection use cases. For example, an enterprise could detect a developer uploading a source-code archive to Claude, identify a user pasting cloud credentials into a chat, or investigate an AI agent that connects to an unapproved MCP server. The organization could then correlate the event with endpoint, identity, cloud, and network telemetry to determine whether the behavior was accidental, malicious, or a policy violation. Claude Enterprise access is controlled at the organization level, with only the Primary Owner able to enable the Compliance API and create access keys. Owners can create keys limited to their own organization, while administrators cannot enable the API. Once connected, Claude events can flow into the organization’s established security dashboards and incident-response processes. According to Claude , enterprises should maintain governance controls by defining AI-use policies, limiting agent permissions, applying least privilege, protecting API keys, reviewing connector access, and setting data-retention rules. As AI tools become embedded in daily business processes, monitoring Claude usage is becoming an important part of enterprise detection and response. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post Security Teams Can Now Check for Claude Chats, Files and AI Agent Activity appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 7h
WaterISAC reckons with range of threats after summer of cyberattacks
cyberscoop.com
WaterISAC reckons with range of threats after summer of cyberattacks
Tom Dobbins, executive director of the Water Information Sharing Analysis Center or WaterISAC, told CyberScoop, the sector’s biggest ongoing weaknesses include exposed OT, vulnerable PLCs, insecure connections through integrators and poor cyber hygiene at smaller utilities, which have pushed the center to make threat sharing faster across the sector.
011
InfoSec @infosec.skyfleet.blue · 7h
RSA Launches Agent ID Platform to Secure AI Agents and MCP Servers
cybersecuritynews.com
RSA Launches Agent ID Platform to Secure AI Agents and MCP Servers
RSA has announced RSA Agent ID, a new identity security platform that helps regulated organizations discover, secure, and govern AI agents. The launch targets financial services, government agencies, critical infrastructure operators, and other organizations that need to control what AI agents can access and prove who authorized sensitive actions. The platform addresses a growing problem in enterprise AI adoption: agents often receive credentials, access internal systems, and perform automated tasks without the same registration, ownership, and access-review controls used for employees and other human users. RSA said AI agents should be treated as identities because they hold credentials and entitlements, while organizations may struggle to identify, assign ownership, and revoke access for every agent. The challenge is expected to grow rapidly as more companies deploy agentic AI. RSA cited Gartner projections that a typical Global Fortune 500 enterprise could operate around 150,000 AI agents by 2028, compared with fewer than 15 in 2025. The company also cited research indicating that only 13% of organizations believe they have the right governance for AI agents. Shadow AI refers to AI tools and agents operating outside approved security, compliance, and IT processes, creating a key organizational concern. RSA Launches Agent ID RSA’s solution brief states that shadow AI incidents can lead to data loss, operational disruption, regulatory penalties, and higher breach costs. It cites an average cost of $5.39 million for security incidents involving shadow AI, about $400,000 more than the average data breach. For banks, public-sector organizations, and critical infrastructure operators, an uncontrolled AI agent could access customer data, initiate payments, use privileged cloud credentials , or interact with sensitive government systems. RSA said these environments require stronger controls than a cloud-only model can provide. RSA Agent ID is available as three standalone modules or as a unified platform: Module Function Key Benefits Discover Finds AI agents and MCP servers; assigns owners, risk tiers, and lifecycle status. Visibility, risk identification, and asset tracking Secure Enforces policies and human approval for high-risk agent actions. Prevents unauthorized actions and reduces security risks Govern Reviews access, automates lifecycle controls, and supports compliance audits. Better access control, governance, and compliance RSA Agent ID Discover is designed to find AI agents and Model Context Protocol servers across identity, cloud, endpoint, and gateway data sources. It creates a registry for known and unknown agents, assigns each a human owner, and records a risk tier and lifecycle state. RSA Agent ID Secure applies policy checks to agent calls through an AI/MCP Gateway. The gateway can operate in an RSA-hosted environment or within the customer’s own cloud, hybrid, or on-premises infrastructure. Organizations can require a named and authenticated human operator to approve high-risk actions, including wire transfers, account access, classified-data access, or actions involving personally identifiable information. RSA Agent ID Govern focuses on lifecycle controls. It supports continuous certification, risk-based access reviews, entitlement controls, and automated decommissioning to prevent agents from retaining access after their tasks or business roles end. RSA offers sovereign control, allowing customers to choose where the gateway runs and policy decisions are made, keeping enforcement and evidence generation within customer-controlled environments. RSA released a platform that generates tamper-evident records of agent actions, access decisions, and gateway calls, with evidence streaming to SIEM platforms and mapping to 10 compliance frameworks, including NIST AI RMF 1.0, ISO/IEC 42001, DORA, and NYDFS Part 500. RSA Agent ID Discover and Secure are scheduled for general availability on November 16, 2026. RSA Agent ID Govern is expected to become generally available during the first half of 2027. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post RSA Launches Agent ID Platform to Secure AI Agents and MCP Servers appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 7h
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
securityaffairs.com
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
Attackers abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT, hiding payloads behind signed software.
010
InfoSec @infosec.skyfleet.blue · 8h
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
cybersecuritynews.com
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal of the malicious application until the phone reboots. Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin America and Southeast Asia. Fake apps lure victims into granting Accessibility access, extending the risks described in earlier RatHat banking attacks with deeper control over the device. Cleafy researchers identified three generations of the malware’s operator panel between April and September 2026. Samples from late 2025, February 2026 and current campaigns retained a similar design, while the infrastructure behind them changed substantially. Earlier campaigns used cryptocurrency trading and adult entertainment decoys. Cleafy said in a report shared with Cyber Security News (CSN) that nearly 100 separate deployments had appeared since April 2026. RATHat Architecture (Source – Cleafy) Licensing restrictions and parallel campaigns support a malware-as-a-service model, rather than proving one central group controls every deployment. RATHat Android Malware After receiving Accessibility access, RATHat navigates the phone’s settings, enables wireless debugging and reads the pairing code displayed on screen. It pairs with the local Android Debug Bridge service, gaining access as the shell user, identified by Android as UID 2000. The pairing process relies on finding specific controls, but fixed instructions can fail on unfamiliar manufacturer interfaces, Android versions or languages. When that happens, the malware sends Gemini a structured description of the live interface and asks where to tap. Gemini returns coordinates or short text that helps resolve an unfamiliar label. Requests go directly from the phone to Gemini Flash models using a key stored in the malware configuration, rather than passing through the attackers’ command server. This resembles the adaptive navigation seen in Gemini assisted Android spyware that replaces rigid screen instructions with model responses. The C2 Panels Observed (Source – Cleafy) In RATHat, however, the observed device-side AI function specifically keeps the wireless-debugging pairing sequence working when ordinary text matching fails. Once pairing succeeds, an operator can deploy a separate service written in Go with one click. It runs independently of the app, opens a local HTTP server on port 7912 and remains reachable through a reverse tunnel to the attacker’s infrastructure. The service can capture screen content and inject touches using Android testing tools without the usual screen-recording prompt or indicator. Cleafy noted that those tools do not work on Android 14 and later, leaving newer devices dependent on app-based capture with user consent. Fraud Infrastructure The command panel evolved from BlackCat into Panda Workshop V5 and V6. V5 introduced operator two-factor authentication and an AI balance-scoring widget, while V6 obscured its frontend code, added phishing download-page templates and consolidated AI settings around Gemini. Operators can build, package, sign and publish malicious apps without leaving the console. Scheduled rebuilding produces fresh files while keeping the underlying implant unchanged, helping campaigns evade detection methods that depend on recognizing previously recorded file hashes. Alongside remote control, the panel exposes stolen messages, credentials, contacts, photographs and files. Fake screens placed over targeted apps capture entered information. Similar ToxicPanda wireless debugging abuse shows why this developer feature has become a concern beyond conventional credential theft. A separate AI function analyzes collected SMS messages to estimate victims’ bank balances and rank devices by value. It helps operators select targets, rather than carrying out fraud itself. Cleafy found no analyzed sample that used AI-guided navigation to complete a fraudulent transfer. Cleafy recommends monitoring activity executed as UID 2000, extending security checks beyond the application’s permissions and lifecycle. Downloaded testing tools retain recognizable filenames in the temporary deployment directory, providing artifacts that investigators can examine during a suspected compromise. The removal gap is important: deleting the visible app does not immediately stop the independent service, which survives until reboot. The research also warns that AI-assisted interface navigation could reduce the custom engineering needed for future automated banking attacks, although that broader capability was not demonstrated here. Indicators of compromise (IoCs):- Type Indicator Description Domain admin.chunhuating[.]best September 2026 command-and-control infrastructure, Panda Workshop V6. Domain admin.xiongmaocs[.]pics August 2026 command-and-control infrastructure, Panda Workshop V5. IPv4 8.231.120[.]246 April 2026 command-and-control infrastructure, BlackCat. Domain admin.rathat[.]live December 2025 and February 2026 command-and-control infrastructure, Fisher. URL https://dramaspoolcoa[.]com/en.html September 2026 delivery page. MD5 116346cace7f00ba557034b534d40791 September 2026 malware sample. URL https://rathat[.]me/app-release-rat-hat-live.apk December 2025 and February 2026 delivery URL. MD5 8fdc21e25097a46528211274e54330e1 February 2026 malware sample. MD5 f83357b2d47c7d38ee53943373961211 December 2025 malware sample. File name app-release-rat-hat-live.apk Android package filename appearing in the source’s delivery URL. File path /data/local/tmp Deployment directory for the native service and downloaded tools; not inherently malicious. File name minicap Legitimate Android testing tool abused for screen capture; not a unique malware indicator. File name minitouch Legitimate Android testing tool abused to inject touch events; not a unique malware indicator. File name screencap Android screen-capture utility used as a fallback; not a unique malware indicator. URI path /api/bin/arm64-v8a/minicap Example command-server path used to retrieve an architecture-specific screen-capture tool. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions appeared first on Cyber Security News .
012
InfoSec @infosec.skyfleet.blue · 8h
CVE-2026-102509: Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
seclists.org
oss-sec: CVE-2026-102509: Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
Posted by Christofer Dutz on Sep 30 Severity: CVSS 4.0: 8.7 (high) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected versions: - Apache PLC4X 0.10.0 before 1.0.0 - Apache PLC4X 1.0.0 unaffected - Apache PLC4X 0.10.0 before 1.0.0 - Apache PLC4X 1.0.0 unaffected Description: Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a...
000
InfoSec @infosec.skyfleet.blue · 8h
CVE-2026-102508: Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
seclists.org
oss-sec: CVE-2026-102508: Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade
Posted by Christofer Dutz on Sep 30 Severity: CVSS 4.0: 9.2 (critical) CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected versions: - Apache PLC4X 0.9.0 before 1.0.0 - Apache PLC4X 1.0.0 unaffected Description: Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read,...
000
InfoSec @infosec.skyfleet.blue · 9h
AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access
cybersecuritynews.com
AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access
Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory write into local root access. The flaw affects the DIBS loopback implementation used by the SMC-D shared-memory communication path, where a missing bounds check allows attacker-controlled data to be copied beyond an allocated kernel buffer. The vulnerability is notable not only for its impact, but for the weakness of the available exploit primitive. XBOW’s research showed that the bug could reliably produce only 16 zero bytes at a partly controlled kernel-memory offset. Despite this limitation, the researchers developed a local privilege-escalation exploit that elevated a process to root without requiring a separate information leak. The issue exists in the dibs_loopback driver, which enables Shared Memory Communications Direct, or SMC-D , on standard x86 Linux systems without IBM Z hardware. SMC-D was historically associated with IBM mainframe environments and Internal Shared Memory devices, leaving much of its code comparatively less scrutinized. The exploit reaching a shell as root (source: Xbow) Adding the dibs_loopback virtual device changed that exposure. It made SMC-D reachable on commodity Linux systems through loopback networking, turning code once considered difficult to access into a local attack surface. AI Agent Finds Linux Kernel Bug XBOW found that a peer-controlled dmbe_idx value could influence offset calculations during SMC connection setup. That offset eventually reached the move_data() routine in the DIBS loopback driver, which performed a memcpy() operation without validating whether the supplied offset and write size remained within the destination buffer. The upstream remediation adds validation for offset and size before the copy operation. Linux advisory information describes the flaw as an out-of-bounds write that could corrupt memory beyond the allocated buffer because software loopback lacks the hardware-enforced memory-region protections available in real ISM hardware. The CLC handshake (Proposal, Accept, Confirm) and the peer-controlled fields the kernel must validate (source: Xbow) The local attack scenario requires CAP_NET_ADMIN. XBOW used that capability to enable SMC-D functionality and manipulate loopback CLC handshake traffic through an NFQUEUE-based man-in-the-middle setup. By modifying selected handshake fields, the exploit could force an out-of-bounds write into adjacent kernel memory. The usable effect was not an arbitrary write: it was a fixed 16-byte zero write positioned at a chosen alignment over a limited range. Rather than attempting to build a more powerful primitive, researchers targeted the Linux kernel’s cred structure, which stores a process’s user and group identity fields. If zero bytes land on fields including euid, the effective user ID becomes zero. Since Linux permission checks treat an effective UID of zero as root, the affected process can subsequently establish a full root identity and spawn a root shell. This approach demonstrates a familiar exploitation lesson: a primitive does not need to be arbitrary to be security-critical. If a restricted write can zero security-sensitive state, it may still be sufficient for privilege escalation. XBOW reported that its proof of concept succeeded on 22 out of 100 separate boots, with the first successful privilege escalation appearing on the seventh boot. 16 zero-bytes overwrite cred , zeroing euid and granting root privileges (source: Xbow) The experiment was performed on Ubuntu 24.04 using Linux 7.1.0-rc6 with kernel mitigations disabled, so that real-world reliability may differ across distributions, kernel builds, allocator behavior, and enabled mitigations. The CVE record carries a CVSS 3.1 base score of 7.8, rated High, with a local attack vector, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact. XBOW said its agent handled threat modeling, code auditing, bug discovery, validation, and much of the exploit-development process. However, human researchers made several important interventions. They redirected the system toward a local privilege-escalation model , encouraged it to revisit packet interception after it initially discarded that option, and required it to validate the restricted zero-write behavior experimentally. Researchers also pushed the agent to exploit the existing primitive directly rather than spending time seeking a more powerful use-after-free or arbitrary-write chain. The findings highlight both the promise and current limits of autonomous vulnerability research . AI systems can sustain exhaustive code analysis and testing across obscure subsystems. However, human judgment can still be decisive when evaluating costly attack paths, correcting stale assumptions, and reframing an exploit strategy. Administrators should apply Linux kernel updates containing the DIBS loopback bounds-check fix and reboot affected systems. Organizations should also review workloads and containers granted CAP_NET_ADMIN, because that capability is central to the demonstrated local attack path. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 9h
New OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators
cybersecuritynews.com
New OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators
A new open-source security tool, OperTraitor, has revealed how Kubernetes operators can create dangerous privilege escalation paths when they receive excessive role-based access control permissions. The tool analyzes operator manifests and compares their documented function with the permissions actually granted to their service accounts. Kubernetes operators automate administrative tasks such as deploying databases, monitoring workloads, and managing infrastructure resources. They use custom resource definitions and controllers to continuously compare a cluster’s desired state with its real state. To do this, operators need Kubernetes service accounts with RBAC permissions. 1qHowever, many operators are given broad permissions for convenience. In some cases, developers use wildcard permissions or cluster-wide ClusterRoles rather than restricting access to the namespaces and resources an operator genuinely needs. If an attacker compromises such an operator through a vulnerable container image, dependency flaw, or supply-chain attack, those permissions can turn a limited breach into a cluster-wide incident. OperTraitors Tool OperTraitor, released by Palo Alto Networks , examines RBAC YAML manifests from locally installed Kubernetes operators and the OperatorHub catalog. OperTraitor’s high-level architecture (source: Palo Alto Networks) It uses an LLM-powered analysis engine to identify differences between an operator’s stated purpose and its actual privileges. The tool then assigns a normalized risk score from 1 to 10, helping defenders identify operators that may need reduced RBAC permissions. The research found that more than 5% of examined operators requested excessive permissions, including potential paths to cluster administrator access. The issue is especially concerning for older or abandoned operators still available through OperatorHub and the Operator Lifecycle Manager. While vendors may publish newer versions through Helm charts, GitHub, or ArtifactHub, outdated releases can remain available in default registries and may still be deployed by users. One case involved IBM’s Prometurbo operator, used with IBM Turbonomic. OperTraitor identified that the operator had cluster-wide permission to get, list, and watch Kubernetes Secrets. This meant a compromised operator could potentially access sensitive data from unrelated namespaces, including service account tokens, database credentials, API keys, and TLS certificates . OperTraitor UI showing risk scores (source: Palo Alto Networks) IBM fixed the issue after responsible disclosure, assigning CVE-2026-6389 a CVSS 8.8 High severity rating and reducing the operator’s permissions to better follow least-privilege principles. OperTraitor also flagged the Datadog operator for broad access to Secrets and RBAC resources such as ClusterRoles and ClusterRoleBindings. Datadog said some permissions were needed because users can define secret names dynamically, making them difficult to restrict in advance. The vendor published documentation explaining its permissions and available mitigations, allowing customers to assess the risk. The findings highlight growing risks as Kubernetes adopts LLM-enhanced and agentic operators , which can make autonomous decisions, call external services, and manage agent lifecycles; excessive RBAC privileges could expose sensitive cluster data or enable unintended actions at scale. Security teams should review every operator’s service account, avoid deploying outdated registry packages, and favor namespace-scoped Roles over cluster-wide ClusterRoles wherever possible. Monitoring Kubernetes audit logs can also help identify unusual behavior, such as an operator attempting to read Secrets from unrelated namespaces. OperTraitor gives defenders a way to detect risky non-human identities before they become a path to full Kubernetes cluster compromise. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post New OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 9h
Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code
cybersecuritynews.com
Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code
A now-patched vulnerability in Unsloth Studio allowed a malicious Hugging Face model repository to execute Python code when a user merely selected the model in the browser interface. Unsloth fixed the issue in version 2026.6.9, and users running Studio should upgrade immediately. Unsloth is a popular open-source library used to fine-tune and quantize large language models. Its Studio component is a browser-based interface, listed as beta, that simplifies model selection, training, and related workflows. The project has significant ecosystem reach: Hugging Face identifies Unsloth as the third-largest source of model derivatives on its Hub, behind Qwen and Google . The flaw was discovered in Unsloth Studio’s backend model-inspection workflow. When an operator chose a Hugging Face model through the interface, Studio checked the model’s configuration before loading weights or starting inference however, the affected code path enabled trust_remote_code=True by default. That setting is powerful but dangerous. Hugging Face model repositories can include custom Python files alongside model weights and configuration data. Unsloth Studio RCE Flaw A repository’s config.json can use the auto_map field to point Transformers components, such as AutoConfig, to those local Python files. If remote code is trusted, the Transformers library imports and executes the repository-provided module. In vulnerable Studio releases, this happened during what appeared to be a harmless metadata inspection. An attacker could create a malicious model repository with a crafted config.json, convince a Studio user to select it, and cause code to run in the Studio backend process. The victim did not need to load model weights, run training, begin inference, or explicitly approve remote code execution. The code would run with the permissions of the user operating Studio. On AI development systems, that may expose Hugging Face tokens , cloud credentials, SSH keys, proprietary datasets, model artifacts, and training outputs. Attackers could also tamper with local models, establish persistence, or use accessible credentials to reach other infrastructure. The vulnerable Studio logic was included in the standard unsloth Python package rather than a separate prerelease-only package. Exploitation required the victim to run Studio and select an attacker-controlled model. However, the affected code could be installed through an ordinary pip install unsloth workflow. Pillar Security reported the issue privately in early June 2026. Unsloth’s maintainers responded and released a fix on June 18. Researchers independently verified that version 2026.6.9 closes the vulnerable Hugging Face and local-directory model-loading paths. The maintainers declined to publish an advisory because Studio was in beta, so no CVE has been assigned. Organizations should upgrade Unsloth Studio to version 2026.6.9 or later. Security teams should also treat any use of trust_remote_code=True as execution of untrusted software, not as a routine model-loading option. Pin model repositories to known revisions, load them in isolated environments, and prevent access to long-lived credentials wherever possible. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 9h
Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software
cybersecuritynews.com
Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software
A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information. The intrusion used legitimate application components as cover, with encrypted files concealing the malware until it was loaded into memory. The affected program came from an Italian developer known for a long-running digital audio workstation. Attackers modified its supporting files and arranged automatic execution through a scheduled task. The investigation did not establish how the altered software first reached the victim’s computer. Researchers from Fortinet’s FortiGuard Incident Response team identified the variant while investigating a compromised device. Fortinet said in a report shared with Cyber Security News (CSN) that the malware combined a staged loader with extensive remote-control and information-stealing capabilities. Also known as ArechClient2, SectopRAT is an existing malware family rather than a newly discovered threat. Earlier malicious search advertising campaigns have delivered it through deceptive downloads. The SectopRAT payload (Source – Fortinet) This investigation documents another concealment method, but does not establish a connection to those campaigns or quantify wider infections. Fortinet Uncovers SectopRAT Variant The attackers changed a legitimate supporting library so it would import an additional malicious component when the application’s reporting executable started. Windows Task Scheduler launched that executable automatically, giving the modified software a way to activate without repeated user interaction. Investigators found the altered application folder outside its normal installation location. Crucially, Fortinet found no evidence that the developer distributed compromised software. The available evidence points to tampering with legitimate files, not a confirmed breach of the vendor’s software supply chain. The first malicious component decrypted assembly code hidden in a database file. Comparison of the IATs of the legitimate and tampered ‘FrameworkBase.dll’ files (Source – Fortinet) It then passed that code through another library and abused a Windows callback function, which normally processes system information, to execute the decrypted instructions instead. That intermediate code resolved 187 Windows functions dynamically, concealing their names until execution. It decrypted the final malware from a second database file, prepared the .NET runtime, and started the 64-bit SectopRAT payload directly in memory. Comparable in-memory malware loading techniques have appeared in other investigations, including Sauron Loader. Here, encryption, indirect calls, and multiple loading stages made the working payload less obvious than a standalone malicious executable sitting openly in an application folder. The payload also replaced readable code names with random ones and complicated its execution flow. These changes layered additional obstacles over a loader already designed to conceal the final program during normal inspection. Frequent calls through method pointers further hindered reverse engineering, making it harder for analysts to follow the malware’s logic and identify its functions. Remote control Once active, SectopRAT decrypted its controller’s address from embedded resources and attempted a connection. If that failed, it contacted one of 12 backup endpoints to recover an alternative address through several decoding and decryption steps. Fortinet noted that these endpoints appeared related to Binance Coin infrastructure, but could not establish whether attackers had compromised them. Their use as fallback channels should not be confused with proof that their operators participated in the intrusion. All traffic between the malware and its controller was AES-encrypted. Researchers identified 29 commands supporting screen capture, remote shell access, file and process management, computer restarts, and other administrative actions that effectively placed the device under outside control. One command downloaded an additional browser extraction module. The malware collected saved passwords, associated website addresses, autofill records, payment-card information, and cookies. Similar browser credential theft campaigns show why a single infected device can expose several valuable accounts at once. The targets extended beyond browsers to Thunderbird, gaming applications, wallet extensions, and desktop cryptocurrency wallets. Collected information was packaged as structured data, encrypted, and sent to the controller. An uninstall command could delete the running executable after a six-second delay. Fortinet recommends security-awareness training to help users recognize phishing and other suspicious content, alongside seeking incident-response assistance when compromise is suspected. Its published indicators provide investigation leads, but legitimate filenames and shared infrastructure require context rather than automatic assumptions of malicious ownership. Indicators of compromise (IoCs):- Type Indicator Description C2 IP and port 98.142.252[.]140:15847 Hardcoded command-and-control server and TCP port. Backup endpoint hxxps://bsc-dataseed1.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed2.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed3.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed4.binance[.]org/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed1.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed2.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed3.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed4.defibit[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed1.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed2.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed3.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Backup endpoint hxxps://bsc-dataseed4.ninicoin[.]io/ Fallback endpoint used to recover a controller address; compromise not established. Download URL hxxp://98.142.252[.]140:9000/wmglb Location serving the additional browser extraction module. SHA-256 48D3ECBB9E0B6BABE6E53E2082A076BAD07EF61CCD98DCC8B9E4F390B937788B Tampered FrameworkBase.dll sample. SHA-256 37FCBCB21D16866784050682C58424C91D3A736F6FD599271FA6E53CF5CA8A92 Malicious sdkcra.dll sample. SHA-256 EFA07701570983909EF923EA79BB032F19FD9DAC0B819FA0E4F6B1161A4CC221 Activation.Desktop.db containing encrypted assembly code. SHA-256 95F6ABD3C43EF4B33CD61D054527233DD2CE705804D44A04BE96CFB73BB52E3A pool.db containing the encrypted SectopRAT payload. File name ReportDump.exe Legitimate reporting component launched through a scheduled task; name alone does not establish compromise. File name FrameworkBase.dll Legitimate library modified to import the malicious loader. File name sdkcra.dll Malicious entry library that begins payload extraction. File name Activation.Desktop.db Database file holding encrypted intermediate code. File name pool.db Database file holding the encrypted final payload. File name WbElevation.dll Downloaded module assisting browser data extraction. File name SDL3.dll Library whose exported file-reading function is used during loading; contextual artifact. File name stp_aim_x64_vc15.dll Library used to invoke the Windows callback that executes decrypted code; contextual artifact. File name mscoreei.dll .NET runtime component loaded before payload execution; legitimate contextual artifact. File name clr.dll .NET runtime component loaded before payload execution; legitimate contextual artifact. File name cmd.exe Legitimate Windows command interpreter used by the uninstall routine. Directory C:\ProgramData Location containing the tampered application folder, outside the software’s normal installation directory. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software appeared first on Cyber Security News .
010
InfoSec @infosec.skyfleet.blue · 10h
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
securityaffairs.com
WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign
Researchers detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access.
000
InfoSec @infosec.skyfleet.blue · 10h
Re: JIT buffer overflow fixed in libpcre2-10.49
seclists.org
oss-sec: Re: JIT buffer overflow fixed in libpcre2-10.49
Posted by Gabriel Ravier on Sep 30 I believe that `gh api repos/PCRE2Project/pcre2/security-advisories/GHSA-r9hj-j2rw-4q3m --jq .description` would give you the plaintext advistory. It is Markdown though - if you want literal plaintext plaintext I guess piping the output of `gh api [etc.] | pandom -f gfm -t plain` would render GitHub's markdown into "proper" plaintext.
000
InfoSec @infosec.skyfleet.blue · 10h
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
darkreading.com
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
013
InfoSec @infosec.skyfleet.blue · 10h
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
thehackernews.com
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Citrix NetScaler CVE-2026-88772 is exploited in the wild and can enable remote code execution through a DTLS buffer overflow.
000
InfoSec @infosec.skyfleet.blue · 12h
MCP Python SDK OAuth Flaw Lets Malicious Servers Hijack AI Agent Accounts
cybersecuritynews.com
MCP Python SDK OAuth Flaw Lets Malicious Servers Hijack AI Agent Accounts
A high-severity flaw in the official Model Context Protocol (MCP) Python SDK could allow a malicious MCP server to steal OAuth authentication material and take over AI agent accounts. The issue affects vulnerable HTTP-based MCP clients that connect to untrusted servers while using OAuth to access legitimate identity providers such as Google, Okta, or Microsoft Entra ID. MCP is an open protocol that lets AI assistants and agents connect with external tools, APIs, and data sources. When an MCP client needs authentication, it performs OAuth discovery to determine which authorization server should handle login. The vulnerable SDK trusted data supplied by the MCP server too heavily, allowing an attacker to redirect sensitive OAuth exchanges to attacker-controlled infrastructure. MCP Python SDK OAuth Flaw The attack begins when a malicious MCP server returns a 404 response to a modern authorization-server discovery request. This forces the SDK to use a legacy fallback path. On that path, the SDK accepted OAuth configuration sent directly by the MCP server. However, it did not validate whether the declared OAuth issuer actually matched the expected login provider. As a result, the attacker could provide a configuration that used the victim’s legitimate identity provider for the browser login page while pointing the OAuth token endpoint to a malicious server. The victim would see a normal sign-in page at the real Google, Okta, or Azure AD domain, making the flow appear legitimate. After successful authentication, the affected SDK could send the authorization code, client secret, and PKCE code verifier to the attacker’s token endpoint. PKCE, or Proof Key for Code Exchange, is intended to stop attackers from using a stolen authorization code. However, because the malicious server received both the authorization code and the PKCE verifier, it could complete the exchange with the real identity provider and obtain a valid access token for the victim’s account. According to Cycode, the flaw also weakened credential-binding protections because the SDK validated stored credentials against an issuer value controlled by the malicious MCP server. An attacker could impersonate the real authorization server, causing the SDK to reuse legitimate credentials and send them to an attacker-controlled endpoint. Affected versions include MCP Python SDK 1.9.1 through 1.29.1 in the 1.x branch and versions 2.0.0 through 2.1.1 in the 2.x branch. Impacted OAuth providers include OAuthClientProvider, ClientCredentialsOAuthProvider, and PrivateKeyJWTOAuthProvider. The deprecated RFC7523OAuthClientProvider may also be affected in older deployments. The interactive OAuth provider was rated 6.5 because user interaction is required, though the genuine login page reduces this barrier, while machine-to-machine providers were rated High at 7.5 for requiring no user interaction. AI agent environments face greater risk when models autonomously select MCP servers, as compromised registries, typosquatting, prompt injection, DNS hijacking , or network compromises can redirect agents to rogue servers. Developers should upgrade to MCP Python SDK version 1.30.0 for the 1.x branch or version 2.2.0 for the 2.x branch. The patched releases validate the authorization-server issuer across discovery paths and reject metadata from an unexpected provider. Organizations using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider must also explicitly configure the expected issuer using the issuer= parameter. They should clear older stored OAuth registrations, rotate exposed client secrets, and revoke tokens if an application may have connected to an untrusted MCP server before patching. MCP servers built with the SDK, local stdio clients, and clients that provide their own tokens or headers are not affected. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post MCP Python SDK OAuth Flaw Lets Malicious Servers Hijack AI Agent Accounts appeared first on Cyber Security News .
021
InfoSec @infosec.skyfleet.blue · 13h
OpenAI Rolled out Codex Security Cloud, an Always-on Application Security Service
cybersecuritynews.com
OpenAI Rolled out Codex Security Cloud, an Always-on Application Security Service
OpenAI has upgraded Codex with Codex Security Cloud, an always-on application security service designed to scan GitHub repositories, monitor incoming commits, investigate flaws, remove duplicate findings, and prepare fixes for human review. The cloud-hosted system keeps operating when a developer’s laptop is closed, bringing continuous, agent-driven vulnerability analysis into Codex workflows. Codex Security Cloud is getting a major upgrade, with access to cyber-capable models through Daybreak Blue included by default. It scans entire GitHub repos, continuously reviews new commits, investigates and deduplicates findings, and prepares fixes for review – even when your… pic.twitter.com/up1hpkiCAK — OpenAI (@OpenAI) September 29, 2026 Available through a plugin in Codex on desktop and the web, Codex Security Cloud is offered as a research preview for ChatGPT Pro, Business, Enterprise, and Edu users. Teams connect GitHub repositories, select a compatible cloud environment, and launch either a full repository scan or ongoing commit monitoring. OpenAI says an initial scan creates a project-specific threat model and examines repository history, while later scans focus quickly on newly introduced code. Unlike conventional static scanners that primarily match code against predefined rules, Codex Security is intended to behave like a security researcher. It reads the wider codebase, runs tests, examines realistic attack paths, and attempts to validate candidate vulnerabilities inside an isolated environment before surfacing them. Findings can include affected code, severity, validation evidence, remediation guidance, and a proposed patch that developers can inspect before creating a draft pull request. The upgrade also includes access to cyber-capable models through Daybreak Blue by default within Codex Security Cloud, without requiring a separate Daybreak application. OpenAI describes Daybreak Blue as supporting authorized defensive work such as vulnerability discovery, triage, secure code review, threat modeling, incident response, malware analysis, and patch validation. However, the bundled access applies only inside the Cloud product and does not grant Daybreak Blue access through other Codex Security products or the API. For security teams, the strongest operational benefit may be reduced alert fatigue. Codex investigates and deduplicates results before presenting them, helping reviewers concentrate on distinct, higher-confidence issues rather than repeatedly triaging noisy alerts. Cloud execution also allows scheduled assessments and commit-by-commit checks to continue independently of local hardware, potentially shortening the window between introducing vulnerable code and identifying it. The service nevertheless requires governance. Repository permissions should follow least-privilege principles, cloud environments must restrict secrets and network access, and every generated patch should undergo developer review and testing before merge. OpenAI’s documentation keeps humans in the approval path: users review evidence, request a fix, examine the resulting patch, and then decide whether to open a draft pull request. Codex Security Cloud therefore represents more than another code-scanning feature. By combining repository-wide context, continuous monitoring, validation, deduplication, and patch preparation, OpenAI is positioning Codex as a persistent defensive engineering assistant. Its effectiveness will depend on finding genuine vulnerabilities without creating new noise and on teams treating autonomous remediation as reviewable assistance, not unquestioned authority. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC The post OpenAI Rolled out Codex Security Cloud, an Always-on Application Security Service appeared first on Cyber Security News .
000
InfoSec @infosec.skyfleet.blue · 13h
Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization
cybersecuritynews.com
Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization
Octopus Deploy has disclosed a high-severity vulnerability in Octopus Server that could allow authenticated users to execute arbitrary code on affected servers through insecure JSON deserialization. Tracked as CVE-2026-101169, the flaw affects Octopus Server deployments on Linux and Microsoft Windows. The company released Security Advisory 2026-10 on September 29, 2026, and urged customers to upgrade immediately because no mitigation is available. The issue was discovered during internal testing by Nathan Willoughby of Octopus Deploy. It was identified on September 4, 2026, while patches were released on September 14, 2026. The vulnerability exists in the way Octopus Server processes JSON content associated with Environment and Project objects. An authenticated user with permission to edit either of these objects can submit specially crafted JSON data. When Octopus Server deserializes that attacker-controlled content, the insecure deserialization issue can be abused to execute arbitrary code within the Octopus Server process. This means the attacker must already have valid access to the Octopus Server instance and enough privileges to modify an Environment or Project. Octopus Server Flaw However, the impact can still be significant in enterprise deployment environments, where Octopus Server may have access to deployment credentials, automation workflows, infrastructure targets, and sensitive application configuration data. Successful exploitation could enable a malicious insider , compromised administrator account, or attacker with delegated project permissions to run code in the security context of the Octopus Server process. The final impact depends on the privileges assigned to that process and the server’s access to connected deployment infrastructure. The vulnerability affects all Octopus Server 2019.4.x releases, all 2020.x through 2025.x releases, and several 2026 feature branches. Affected releases include 2026.1.x versions earlier than 2026.1.11781, 2026.2.x versions earlier than 2026.2.13441, 2026.3.x versions earlier than 2026.3.15829, and 2026.4.x versions earlier than 2026.4.1619. Octopus Deploy stated that customers running Octopus Server version 2026.3.15829 or later are not affected. The latest recommended release is version 2026.3.15863. The 2026.4.x release line was only available to Octopus Cloud when the fix was issued. Octopus Cloud customers do not need to take action because the company has already updated all cloud instances to patched versions. Organizations should upgrade Octopus Server to the latest available version as soon as possible. Customers unable to move to the latest build should install a fixed release appropriate to their feature branch. For legacy versions from 2019.4.x through 2025.x, Octopus Deploy recommends upgrading to version 2026.1.11781 or later. Customers using the 2026.2 branch should install version 2026.2.13441 or later, while 2026.3 users should upgrade to version 2026.3.15829 or later. Octopus Deploy has assigned the vulnerability a high severity rating. The company said it is not aware of public exploitation or malicious use of CVE-2026-101169 at the time of disclosure. Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization appeared first on Cyber Security News .
000