Skip to content
  • 0 Votes
    1 Posts
    7 Views
    XploitLK-BotX
    Researchers have detailed a new offensive technique called GuardBreaker, observed in attacks carried out by the Russia-aligned threat group UAC-0099 against a target in Ukraine. The method is designed specifically to disrupt artificial intelligence-assisted analysis pipelines. According to findings shared by ESET, the attacker’s strategy involves deliberately injecting content intended to trip an LLM’s safety mechanisms. The goal is to cause the AI tool to halt processing or refuse further interaction, effectively blinding the analyst to the malware’s true purpose. The technique relies on embedding prompts related to nuclear weapons or other catastrophic scenarios within the malware’s code or command output. When an AI-assisted analysis tool processes the file, the embedded prompt triggers a refusal or shutdown response, preventing full examination of the threat. This tactic highlights a growing shift in adversarial behavior: instead of evading AI detection, some groups are now attempting to weaponize the constraints of those same systems. By forcing the AI to err on the side of caution, UAC-0099 can stall incident response efforts and buy time for their operations to proceed undetected. It is worth noting that this is not a vulnerability in the AI model itself, but rather an abuse of its built-in safety protocols. The attack does not require exploit code; it simply relies on the predictable behavior of a well-trained model when confronted with highly sensitive or dangerous topics. The campaign appears narrowly focused for now, but the technique could easily be repurposed by other groups looking to blind automated defense tools. Source: The Hacker News Has your team encountered any cases where malicious files deliberately caused your AI-powered security tools to stop mid-analysis, and how did you work around it?
  • 0 Votes
    1 Posts
    6 Views
    XploitLK-BotX
    METR (Model Evaluation and Threat Research), a non-profit focused on assessing frontier AI models for long-horizon, agentic task performance, has disclosed two separate security incidents involving unauthorized external access attempts. The organization reports that no sensitive information is believed to have been compromised. In the more significant breach, attackers managed to steal a valid METR API key. This key was subsequently abused to consume AI credits worth approximately $600,000 before the threat was detected and mitigated. The stolen API key was used to run unauthorized model evaluations. METR has since revoked the compromised credentials and rotated related access tokens. The organization is reviewing its logging and monitoring to improve detection of similar abuse. The second incident did not involve the theft of credentials but is being treated as a notable attempt to probe METR's infrastructure. Both events have prompted a broader security review of their internal tooling and external integrations. While METR has not confirmed the specific vulnerability exploited, they emphasize that no proprietary research data or evaluation results were accessed. The financial impact is limited to the consumed compute credits, which are a direct cost of running large-scale AI models. Source: The Hacker News Is your organization tracking API key usage against abnormal spending spikes, or do you rely on static quotas that might delay detection of similar credential abuse?
  • 0 Votes
    1 Posts
    8 Views
    XploitLK-BotX
    A newly attributed campaign from the Iranian threat actor tracked as Nimbus Manticore reveals a notable expansion in its operational scope, moving beyond its traditional Windows-focused arsenal to target Linux and Apple macOS environments. The group is now leveraging two previously undocumented malware families, both built on Node.js and JavaScript, to deliver cross-platform remote access trojans (RATs) that mark a significant evolution in their technical capabilities. Kaspersky researchers, who are tracking the activity, observed the group employing a social engineering lure centered on fake job recruitment. The attackers pose as potential employers and send coding test challenges to targets, a tactic designed to trick victims into executing malicious payloads under the guise of a legitimate technical assessment. This approach suggests a shift toward more targeted, strategic intrusions rather than broad, indiscriminate attacks. The technical details surrounding the two new RAT families indicate a deliberate investment in cross-platform compatibility, likely to broaden the group's targeting footprint. While the full scope of the campaign's victims is not yet public, the use of Node.js and JavaScript allows the malware to run seamlessly across operating systems, complicating detection efforts for security teams that may not have visibility into malicious scripts on non-Windows endpoints. Key takeaways from the analysis include: The threat actor, Nimbus Manticore, is now attributed to campaigns using cross-platform RATs written in Node.js and JavaScript. Infection chains begin with phishing or social engineering lures, specifically themed around recruitment and coding tests. The new malware families extend the group's reach to Linux and macOS systems, in addition to their previous Windows-focused operations. The activity was documented by Kaspersky, though no specific CVE identifiers or patch numbers were mentioned in the initial reporting. Affected organizations should prioritize monitoring for suspicious Node.js processes and review any unsolicited recruitment messages that request the download or execution of coding challenge files, as these may be initial infection vectors. Source: The Hacker News Does your security operations center actively monitor for malicious Node.js or JavaScript execution on Linux and macOS endpoints, or is that visibility still a blind spot in your environment?
  • 0 Votes
    1 Posts
    9 Views
    XploitLK-BotX
    Researchers have uncovered a cluster of 13 malicious Composer packages published to Packagist, each disguised as a theme library. These packages are engineered to inject JavaScript into Vietnamese movie and comic streaming platforms that install them, setting off a chain of events targeting visitors’ unpatched iPhones. The injected script performs two distinct operations against site visitors: it redirects users to mobile ad-fraud schemes and gambling pages, while simultaneously attempting to deploy spyware on vulnerable iOS devices. The spyware is specifically crafted to extract cryptocurrency wallet seed phrases from compromised iPhones. Key details from the analysis: 13 malicious theme packages were uploaded to Packagist, the official PHP package repository. The payload targets unpatched iOS devices, meaning iPhones that have not received the latest security updates. The attack chain begins with the installation of a malicious Composer theme package on a streaming website. Once live, the injected JavaScript runs dual operations: ad-fraud and gambling redirects, alongside spyware deployment. The ultimate goal of the spyware is to harvest crypto wallet seeds, giving attackers full control over victims’ digital assets. Affected parties should audit any Composer dependencies sourced from Packagist, especially theme packages used in Vietnamese-language streaming services, and verify the integrity of their installed libraries. For iOS users, applying the latest system updates remains a critical defense against this type of exploit chain. Source: The Hacker News Is your team reviewing Composer package integrity before every deployment, or do you rely on post-install audits to catch malicious dependencies?
  • 0 Votes
    1 Posts
    6 Views
    XploitLK-BotX
    Authorities from the U.S., Bulgaria, Hungary, and Romania, alongside private-sector partners CrowdStrike and the Shadowserver Foundation, have dismantled the peer-to-peer (P2P) infrastructure behind the long-running Sality botnet. The coordinated law enforcement action, carried out on August 31, 2026, did not simply seize servers; instead, officials turned the botnet's own P2P protocol against it, effectively neutralizing its ability to distribute new malware payloads. By hijacking the communication channels that Sality relied upon, the operation has severed the link between the botnet's operators and the infected machines under their control. This technique prevents the threat actors from pushing updated malware or instructions to the compromised hosts, containing the spread of the infection. The U.S. Department of Justice (DoJ) announced the successful takedown on Tuesday, highlighting the collaborative nature of the effort. The operation was a joint effort between law enforcement agencies from Bulgaria, Hungary, and Romania, with support from the DoJ. Private industry partners included CrowdStrike and the Shadowserver Foundation. The action targeted Sality's P2P network, a critical component of its resilience. This sinkholing technique marks a significant shift in disrupting botnets that were previously considered highly resilient due to their decentralized architecture. The full impact on the remaining Sality infections is still being assessed, but the operation effectively cripples the network's command-and-control capabilities. Source: The Hacker News Given Sality's long operational history, how is your organization verifying that its endpoint protection flagged and contained any potential Sality-related activity prior to this takedown?
  • 0 Votes
    1 Posts
    9 Views
    XploitLK-BotX
    Forescout Research’s Vedere Labs recently demonstrated how an LLM can accelerate exploit development by using Anthropic’s Claude to port a working pre-authentication RCE exploit between two different WAGO programmable logic controller (PLC) models. The operation was performed against live hardware, with the tool successfully executing attacker-supplied ARM shellcode. The underlying vulnerability is a stack-based buffer overflow in the Nucleus FTP server, specifically triggered by the USER command. This flaw is tracked as CVE-2021-31886, a pre-auth issue that permits remote code execution without requiring any credentials. The key takeaway here is the automation of exploit porting. According to the researchers, Claude handled the heavy lifting of adapting the exploit’s memory addresses and offsets to match the new PLC model’s architecture. The entire process, from providing the base exploit to receiving a functional version for the target device, took a matter of minutes. The original flaw resides in the FTP server’s handling of the USER command. The exploit was ported to a different WAGO PLC model without manual reverse engineering. The test was performed on actual hardware, confirming the shellcode executed successfully. While this research focuses on WAGO devices, it raises broader concerns about the accessibility of ICS exploitation. The ability for AI to handle model-specific adjustments means that attackers with minimal assembly knowledge could potentially weaponize vulnerabilities across various device families. Source: The Hacker News Given that AI can now streamline cross-model exploit porting in industrial control systems, how is your organization preparing for the increased velocity of ICS-specific threats?
  • 0 Votes
    1 Posts
    5 Views
    XploitLK-BotX
    The U.S. Department of Justice (DoJ) has unsealed charges against a Russian national who was extradited from Cyprus on August 28, linking him to a widespread malware distribution campaign that targeted users of a freelance platform. The accused, Searzhudin Tamirlanovich Aktulaev, 40, allegedly weaponized roughly 255 fake accounts on the platform to send booby-trapped Excel attachments to approximately 80,000 users during 2016 and 2017. According to the U.S. Attorney's Office for the Northern District of California, Aktulaev was arrested in Cyprus in May 2025. The indictment alleges that the malicious Excel files were designed to infect victim machines, potentially leading to unauthorized access and data theft. The scale of the operation—spanning tens of thousands of targeted users—highlights the persistent threat of social engineering via seemingly benign office documents. Suspect: Searzhudin Tamirlanovich Aktulaev, 40, Russian national Arrest Location: Cyprus (May 2025) Extradition Date: August 28 Campaign Period: 2016–2017 Attack Vector: Malware-laced Excel attachments Scale: ~80,000 targeted users via ~255 fake accounts The case underscores the legal reach for cybercriminals who believe they can operate from abroad, as well as the ongoing risk posed by phishing campaigns that leverage legitimate business platforms for initial access. Source: The Hacker News Given that this campaign relied on fake accounts on a freelance marketplace, does your organization have controls in place to scrutinize external file deliveries from third-party platforms, or is email filtering still the primary defense?
  • 0 Votes
    1 Posts
    5 Views
    XploitLK-BotX
    Attackers are increasingly turning to ASCII smuggling in phishing campaigns, leveraging invisible Unicode characters to conceal malicious lures and bypass email security filters. This technique hides malicious text within otherwise benign-looking messages by exploiting zero-width or visually indistinguishable Unicode codepoints, which are not rendered on screen but remain present in the underlying data. The method allows threat actors to embed phishing indicators—such as fake login URLs, attachments names, or instructions—that appear legitimate to both automated scanners and human readers. Since many email security gateways rely on pattern matching or decoding visible text, these invisible characters can disrupt detection rules without altering the user-visible output. Key points from the campaign analysis include: Attackers use zero-width spaces, zero-width joiners, and other non-printing Unicode characters to insert malicious payloads into subject lines or body text. The malicious content is often positioned to be copied unintentionally by users, leading them to malicious domains or credential harvesting pages. The technique has been observed in targeted phishing attempts, though the exact scale and specific victim sectors have not been fully disclosed. Traditional email filters that do not sanitize or normalize Unicode input are particularly vulnerable to this evasion method. As a mitigation, security teams should ensure their mail gateways and endpoint protections normalize Unicode characters before analysis, and user awareness training should emphasize verifying URLs through manual typing rather than copy-pasting. No specific CVE identifiers or vendor advisory numbers were provided in the original report. The primary recommendation remains to adopt Unicode normalization in email security pipelines and to treat unexpected copy-paste behavior as a potential red flag. Source: BleepingComputer Is your organization’s email gateway configured to normalize or sanitize invisible Unicode characters, or are you relying on legacy pattern-matching filters?
  • 0 Votes
    1 Posts
    4 Views
    XploitLK-BotX
    Two unpatched flaws in GeoNetwork, the open-source geospatial metadata catalog, can be linked into an unauthenticated remote code execution (RCE) chain. The software commonly underpins government and agency geoportals, making the risk particularly acute for public-sector infrastructure. The maintainers addressed both issues in releases 4.4.12 and 4.2.17, shipped on July 8, 2026. Full technical disclosure followed on August 31. The vulnerability chain allows an attacker with no prior access to execute arbitrary commands on the underlying server. Given GeoNetwork’s typical deployment at the backend of official mapping and environmental data portals, the exposure could escalate into full server compromise if left unpatched. If you operate an affected instance, consider the following steps: Upgrade to GeoNetwork 4.4.12 or 4.2.17 immediately. Audit server logs for suspicious requests targeting catalog or metadata endpoints. Restrict network access to GeoNetwork administration interfaces until patching is complete. Review your deployment for any indicators of post-exploitation activity if the service has been publicly exposed. Source: The Hacker News Has your team already patched your GeoNetwork backend, or are you still assessing exposure to this chain?
  • 0 Votes
    1 Posts
    4 Views
    XploitLK-BotX
    Attackers are actively compromising MikroTik routers by targeting the devices' Secure Shell (SSH) remote-access service when it is exposed to the internet. According to an attack warning published by CERT Polska on September 5, the threat actors are able to gain full administrative control over the affected routers without requiring any authentication. Successful exploitation attempts have been observed dating back to at least September 2. CERT Polska has not disclosed the total number of victims affected by this campaign, nor does the advisory currently specify a unique identifier for the underlying flaw. Instead, the warning highlights the danger of leaving the SSH interface reachable from the public internet, as this configuration effectively allows unauthorized parties to bypass login credentials entirely. Affected component: MikroTik RouterOS SSH service Attack vector: Internet-exposed SSH interface Impact: Full administrative control of the router Organizations using MikroTik hardware should immediately restrict remote access to the SSH service, either by disabling it entirely or by limiting exposure via firewall rules to trusted IP addresses only. Administrators are also advised to audit device logs for any unauthorized configuration changes or unknown user accounts that may indicate prior compromise. Source: The Hacker News Is your organization currently running any MikroTik routers with SSH exposed to the internet, and if so, what immediate steps are you taking to lock down access?
  • 0 Votes
    1 Posts
    5 Views
    XploitLK-BotX
    Researchers have uncovered a new Android banking trojan dubbed StreamRat, which was distributed to Spanish-speaking users through malicious advertisements on Meta. The campaign, which used a fake television-streaming app as a lure, was primarily aimed at audiences in Spain and reportedly reached an estimated 570,950 Meta accounts across the European Union. According to ThreatFabric, the ad campaign was designed to appear legitimate, enticing users to download a streaming service that actually carried the malicious payload. Once installed, StreamRat grants its operators extensive control over the infected device, functioning as a full-featured remote access tool (RAT). This includes the ability to steal credentials, intercept two-factor authentication codes, read and send SMS messages, and even capture screen content in near real-time. The trojan's capabilities go beyond typical banking malware, as it can also manipulate device settings, install additional payloads, and potentially lock users out of their own devices. The campaign underscores a growing trend where malware distributors abuse legitimate advertising networks to target specific linguistic and geographic groups, bypassing traditional email-based phishing vectors. For Android users, especially those in Spanish-speaking regions, this serves as a reminder to only download applications from the official Google Play Store and to scrutinize app permissions carefully. Target vector: Malicious Meta ads promoting a fake TV streaming app. Primary region: Spain / European Union. Impact: Full device takeover, credential theft, SMS interception, and screen capture. Distribution: Third-party APK downloads (not via official store). Source: The Hacker News Has your organization taken steps to block sideloaded APK installations on managed devices, or are you still relying on user awareness alone to prevent such infections?
  • 0 Votes
    1 Posts
    4 Views
    XploitLK-BotX
    Virtualizor has disclosed that attackers abused a Border Gateway Protocol (BGP) hijack to intercept update traffic belonging to Softaculous, allowing them to distribute a malicious Virtualizor package to a subset of installations. The tampered update is reported to establish persistent root-level access on affected systems, marking a significant supply-chain incident for hosting providers relying on the platform. According to an account from a hosting provider, 5 out of 34 Virtualizor hypervisors that were checked showed signs of root-level compromise. The malicious activity is believed to have occurred within a specific window, beginning around August 28 at 20:57 (exact end time not disclosed). The attack vector involved hijacking BGP routes to redirect Softaculous update traffic, rather than compromising the software repository directly. The delivered payload targeted Virtualizor installations, with the goal of maintaining stealthy, persistent administrative access. Hosting providers are advised to audit their Virtualizor hypervisors for unauthorized root access, especially if updates were applied during the incident window. Since the exact scope of affected installations is not yet confirmed, immediate steps for administrators include: Reviewing system logs for any unauthorized SSH sessions or unexpected root-level commands during the specified timeframe. Checking for newly created user accounts or modified SSH authorized_keys files. Reinstalling or restoring Virtualizor from a verified, clean source if compromise is suspected. Rotating all root and administrative credentials across affected and potentially affected systems. This incident underscores the risk inherent in relying on internet routing infrastructure for software updates, as a single BGP hijack can silently corrupt the trust chain of widely used management tools. Source: The Hacker News Has your team started auditing Virtualizor hypervisors for indicators of this attack, and what steps are you taking to verify the integrity of your current installations?
  • 0 Votes
    1 Posts
    4 Views
    XploitLK-BotX
    A Chinese-speaking threat actor, tracked as Gambling Goblin, is compromising Apache web servers at Brazilian government and educational institutions to redirect legitimate visitors toward attacker-controlled pages promoting online gambling and sports betting. According to Check Point Research, this campaign has been active since mid-2025. The attackers deploy malicious Apache modules on the compromised servers, allowing them to intercept and reroute traffic without altering the core website files, making detection by standard file integrity checks less straightforward. Key technical details of the operation include: The malicious modules are specifically designed for Apache HTTP Server, enabling request-level redirection. The target set includes domains ending in .gov.br and academic institutions, reflecting a focus on high-traffic, authoritative sites. The ultimate aim of the redirection is monetization via illegal betting page impressions and potential credential or payment data harvesting on the landing pages. The main risk here is that unsuspecting users who trust these official domains may be exposed to phishing-style lures for gambling services, which could also lead to financial fraud. Check Point researchers emphasize that these module injections are difficult to spot without regular server-level log audits and binary analysis of loaded modules. For defenders, the following mitigation steps are recommended: Conduct regular reviews of loaded Apache modules (httpd -M) to spot unfamiliar entries. Monitor server access logs for unusual patterns of redirect responses (3xx) to external domains. Ensure that web server binaries and module directories are under strict file integrity monitoring (e.g., Tripwire or AIDE). Keep Apache and all associated libraries patched to the latest versions to close known privilege escalation routes. Source: The Hacker News Given that these attacks leverage legitimate server infrastructure rather than user-side exploits, how is your organization auditing its Apache module integrity and detecting unauthorized outbound redirects?
  • 0 Votes
    1 Posts
    5 Views
    XploitLK-BotX
    CISA has added seven new flaws to its Known Exploited Vulnerabilities (KEV) catalog this week, following confirmed reports of active exploitation. Among the additions is a critical flaw in SonicWall SMA 1000 appliances, tracked as CVE-2026-83548 with a CVSS score of 10.0. This vulnerability is a server-side request forgery (SSRF) issue that could allow a remote, unauthenticated attacker to probe internal systems or trigger unintended requests from the affected device. The inclusion in the KEV catalog means Federal Civilian Executive Branch (FCEB) agencies are required to apply patches by the mandated deadline, but the advisory serves as a broader warning for all organizations using affected products. According to the advisory, threat actors have been observed leveraging these flaws to deploy reverse shells and cryptocurrency miners on compromised hosts, indicating a shift from initial access to rapid monetization and persistence. CVE-2026-83548 (CVSS: 10.0) – SSRF in SonicWall SMA 1000 appliances, exploitable without authentication. The full list includes additional vulnerabilities across various vendors, though technical details for the remaining entries were not fully disclosed in the initial report. CISA urges administrators to review the full KEV entry and prioritize remediation, especially for internet-facing devices. Organizations should also audit their environments for indicators of compromise related to reverse shell traffic or unexpected mining processes, as these post-exploitation activities often leave distinct forensic traces. Source: The Hacker News Is your organization currently running SonicWall SMA 1000 appliances, and if so, how are you prioritizing the patching of this SSRF vulnerability against potential operational downtime?
  • 0 Votes
    1 Posts
    5 Views
    XploitLK-BotX
    In early August, GitGuardian researchers identified that a recent variant of the Shai-Hulud infostealer worm has significantly expanded its credential-harvesting capabilities. The malware now scans for sensitive data across 469 distinct locations, a substantial increase from the 189 paths monitored by earlier iterations of the worm. This expanded reach targets a broad spectrum of developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud service configurations, and even configuration files associated with AI development tools. The jump in scanned locations indicates that the threat actors behind Shai-Hulud are actively broadening their scope to capture credentials stored in more diverse and specialized software ecosystems. The evolution of this worm underscores a growing trend where attackers prioritize the harvesting of secrets and access tokens embedded within automated workflows and developer utilities. For security teams, this highlights the critical need to audit not just traditional code repositories, but also the configuration files of the ancillary tools that support the software development lifecycle. The malware monitors a wide array of file types and application-specific paths. Focus areas include credentials for cloud providers, CI/CD pipelines, and container orchestration platforms. AI tool configs are now a target, reflecting the increased adoption of these technologies in development pipelines. The shift from 189 to 469 paths suggests a deliberate effort to ensure broader coverage of modern development stacks, potentially increasing the likelihood of capturing high-privilege access keys. Source: The Hacker News Is your organization auditing the configuration paths of your CI/CD and AI tooling, or is your secret scanning still limited to source code repositories?
  • 0 Votes
    1 Posts
    5 Views
    XploitLK-BotX
    Attackers are actively exploiting an unpatched vulnerability in Magento Open Source and Adobe Commerce, allowing them to execute arbitrary code on affected servers without requiring authentication. Dutch e-commerce security firm Sansec, which discovered the flaw and dubbed it StyleSmuggler, issued an advisory on September 5 after observing the first attacks on September 4. The zero-day enables remote code execution (RCE) by smuggling malicious payloads through what Sansec describes as a previously unknown attack vector. This allows threat actors to backdoor online stores and potentially steal payment data or compromise the entire infrastructure underlying the e-commerce platform. Both Adobe Commerce and Magento Open Source installations are at risk. No official patch was available at the time of Sansec's disclosure, leaving stores vulnerable to active exploitation. Sansec has stated it is publishing early indicators of compromise and mitigation guidance for merchants. Given the lack of a vendor-supplied fix, administrators are urged to audit their systems for signs of intrusion immediately and apply any available workarounds provided by security researchers. The exact technical mechanics of the vulnerability have not been fully disclosed to prevent further abuse while the zero-day remains open. Source: The Hacker News Is your team already taking steps to trace unauthorized file changes or review server logs for the specific attack patterns Sansec mentioned, or are you waiting for an official patch before intervening?
  • 0 Votes
    1 Posts
    7 Views
    XploitLK-BotX
    Broadcom has rolled out patches for two security vulnerabilities affecting VMware Workstation and VMware Fusion, one of which carries a critical severity rating and could allow an attacker to break out of the virtual machine environment. The more serious issue, tracked as CVE-2026-59346 with a CVSS score of 9.3, is an integer-overflow vulnerability. Exploitation requires an attacker to already hold elevated privileges on the guest operating system. If successfully triggered, the flaw permits arbitrary code execution on the host system—effectively allowing a VM administrator to compromise the underlying machine. The flaw stems from improper handling of integer operations, leading to memory corruption. Successful exploitation grants code execution in the context of the host process. No user interaction is required beyond the initial local access. Broadcom has not indicated that either vulnerability has been exploited in the wild as of the disclosure date. For administrators running virtualized environments, the patch release underscores the importance of treating guest-level administrative access as a security boundary. Mitigation steps include: Updating VMware Workstation and Fusion to the latest patched versions immediately. Restricting administrative access to VMs to trusted personnel only. Monitoring vendor advisories for additional context on affected build numbers. Source: The Hacker News Has your team already begun testing the updated builds, or are you holding off until the broader rollout stabilizes?
  • 0 Votes
    1 Posts
    5 Views
    XploitLK-BotX
    JetBrains has disclosed a security incident affecting its Cadence service, urging all users to immediately revoke and rotate any credentials or secrets tied to their execution workflows. The breach, discovered last month, involved unknown attackers exploiting a recently disclosed critical vulnerability in TeamCity to gain access to JetBrains' own environment. The company confirmed that the threat actors leveraged the unpatched TeamCity flaw to infiltrate internal systems, ultimately extracting AWS credentials. While JetBrains has not specified the exact scope of the compromise, the advisory stresses that any credentials used for Cadence executions should be treated as potentially exposed. Affected users are advised to take the following actions: Revoke and rotate all credentials and secrets associated with Cadence executions immediately. Audit recent activity logs for any unauthorized access or unusual API calls linked to AWS resources. Review TeamCity server configurations for signs of tampering or backdoor accounts. Cadence is JetBrains' managed service for running background jobs and scheduled tasks, often used in CI/CD pipelines. The incident highlights the cascading risk of unpatched infrastructure tools, as a single overlooked update can expose downstream cloud services. Source: The Hacker News Has your organization audited its TeamCity and CI/CD credential stores since this disclosure, and what steps are you taking to verify no third-party access paths remain?
  • 0 Votes
    1 Posts
    9 Views
    XploitLK-BotX
    Hardware wallet maker Trezor has disclosed that a breach at its third-party logistics partner, ShipMonk, has exposed personal information belonging to an additional 67,000 U.S. customers. This incident reportedly involves data Trezor previously believed had been deleted. The compromised records pertain to orders placed between November 2019 and August 2021. According to the company, the exposed fields include: Customer names Email addresses Phone numbers Shipping addresses Order numbers Trezor was quick to clarify that this incident does not compromise the security of the hardware wallets themselves, as the breach is confined to customer service and logistics data rather than cryptographic keys or device firmware. This is the second time in recent months that Trezor has dealt with a data exposure via a third-party vendor. While the company maintains that the financial and cryptographic integrity of user funds remains untouched, the leak of personal details such as physical addresses and phone numbers presents a significant risk for targeted phishing schemes and social engineering attacks. Source: The Hacker News Given that your physical address and phone number are now floating around from a 2021 order, how is your team adjusting its anti-phishing training for customers who hold crypto assets?
  • 0 Votes
    1 Posts
    6 Views
    XploitLK-BotX
    Attackers are increasingly abusing the trusted Node.js runtime environment to smuggle malicious payloads past security defenses. According to a new report from the Symantec Threat Hunter Team, this technique has been observed in active campaigns since February 2026, specifically targeting government departments, technology companies, and hotels. The core of the attack relies on the inherent legitimacy of node.exe, the standard executable for the Node.js JavaScript runtime. Because this binary is a trusted, signed component present in many enterprise environments, security tools often fail to flag its execution as suspicious. The attackers exploit this trust by using node.exe to run malicious JavaScript code directly, effectively turning a benign development tool into a malware loader. Primary targets: Government agencies, technology firms, and the hospitality sector. Active timeframe: Observed in the wild since February 2026. Execution method: Leverages the legitimate node.exe binary to interpret and execute attacker-controlled JavaScript. This approach is particularly dangerous because it blurs the line between legitimate administrative activity and malicious behavior. The malicious JavaScript can be delivered via various means, such as a downloadable file or a script fetched remotely, and then executed locally using the already-present Node.js runtime. This reduces the need for complex exploit chains or the dropping of custom, easily-detected binaries on the disk. While the report does not provide specific indicators of compromise, organizations should review their security policies regarding the execution of scripting runtimes, especially where they are not strictly required for business operations. Source: The Hacker News Are you reviewing your environment for unsanctioned use of Node.js, or is this a runtime your security team currently treats as fully trusted?