Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending

World

Topics from outside of this forum. Views and opinions represented here may not reflect those of this forum and its members.

Help
Load new posts
Log in to post

A world of content at your fingertips…

Think of this as your global discovery feed. It brings together interesting discussions from across the web and other communities, all in one place.

While you can browse what's trending now, the best way to use this feed is to make it your own. By creating an account, you can follow specific creators and topics to filter out the noise and see only what matters to you.

Ready to dive in? Create an account to start following others, get notified when people reply to you, and save your favorite finds.

Register Login
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Data Breaches & Incidents
    French hospital fined €500,000 after breach exposes data of 727,000

    France’s data protection authority, the CNIL, has imposed a €500,000 ($580,000) fine on Hôpital privé de la Loire following a breach that exposed the personal data of roughly 727,000 individuals, including patients and their relatives.

    The penalty stems from the hospital’s failure to implement adequate security measures, which allowed attackers to gain access to sensitive records. According to the CNIL’s findings, the incident was traced back to a public-facing application that lacked sufficient access controls. The hospital also failed to set up proper authentication protocols, and did not monitor the affected system for suspicious activity in real time—gaps that directly facilitated the unauthorized access.

    • The breach reportedly occurred in early 2021.
    • Data exposed included names, social security numbers, dates of birth, medical information, and contact details of patients and their relatives.
    • The attackers were able to exfiltrate documents and post some of the stolen data on underground forums.

    The CNIL’s investigation highlighted several specific shortcomings, including the absence of a web application firewall and a lack of systematic logging. Furthermore, the hospital did not promptly review available system logs after the intrusion was discovered, which delayed containment and harm assessment. The fine reflects the regulator’s view that the facility’s security posture was clearly insufficient for the volume of sensitive healthcare data it handled.

    This case underscores that healthcare organizations remain prime targets for cybercriminals, and regulators are increasingly willing to issue heavy financial penalties when basic security hygiene is neglected.

    Source: BleepingComputer

    Do you think your organization’s access controls and monitoring practices would withstand a CNIL-style audit, or are you relying on compliance checklists rather than real-world resilience?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Coder's registry infrastructure compromised to push malicious modules

    Attackers gained access to Coder’s Cloudflare-backed infrastructure and inserted unauthorized registry servers that distributed malicious Terraform modules designed to steal credentials. The compromised modules were served to developers who pulled from Coder’s public registries during a targeted window, with the tampered code executed locally when Terraform initialized the modules.

    The incident highlights a supply-chain risk in infrastructure-as-code workflows — the malicious modules were not flagged by typical signature checks, as the attackers abused legitimate registry endpoints. Organizations that used Coder’s registry during the exposure period should treat any downloaded modules as potentially untrusted and audit recent Terraform state and plan outputs.

    • Review any Terraform modules fetched from Coder’s registry for unexpected submodules or remote data sources.
    • Rotate cloud provider credentials, API keys, and any secrets that may have been exposed to the local environment during module execution.
    • Inspect shell history and logs for suspicious outbound connections or newly created background processes on developer workstations.
    • Re-run dependency and module integrity checks against known-good hashes if available from your own internal mirror.

    No specific CVE identifier was disclosed in the report, and the exact duration of the compromise has not been published.

    Source: BleepingComputer

    Has your team audited Terraform module integrity after this disclosure, or are you relying on registry-side verification alone?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    🔴 Critical: HPE patches critical ArubaOS-CX remote code execution flaw

    Hewlett Packard Enterprise has released security updates addressing a critical remote code execution vulnerability in ArubaOS-CX, the operating system powering its data center switch portfolio. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code on affected devices, potentially leading to full compromise of the network infrastructure.

    The flaw stems from improper handling of user-supplied input in the operating system. An attacker able to reach the management interface could leverage this weakness to inject and run commands with elevated privileges, bypassing authentication altogether.

    Administrators are urged to act quickly, as the vulnerability is rated critical in severity. HPE has not reported any active exploitation in the wild at the time of the advisory, but the attack surface is significant given the widespread deployment of ArubaOS-CX in enterprise and data center environments.

    The following actions are recommended for mitigation:

    • Upgrade affected devices to the latest patched ArubaOS-CX version provided in the HPE security bulletin.
    • Restrict access to management interfaces (SSH, HTTPS, SNMP, and CLI) to trusted administrative networks only.
    • Disable any unused management protocols to reduce the attack surface.
    • Monitor device logs for unusual activity or unauthorized configuration changes.

    Network teams running Aruba switches should verify their current firmware version and compare it against the patched release immediately.

    Source: BleepingComputer

    Has your team already checked the ArubaOS-CX version in your environment against the new advisory, and if so, are you planning a maintenance window for the upgrade this week?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    🔴 Critical: Critical Elementor Pro flaw exploited to take over WordPress sites

    A critical authentication bypass vulnerability in Elementor Pro for WordPress, tracked as CVE-2026-32475, is now being actively exploited in the wild. Attackers are leveraging the flaw to deploy webshell payloads, granting them the ability to execute arbitrary commands directly on the affected server.

    The flaw, which was patched in a recent update, allows unauthenticated attackers to bypass access controls and take over vulnerable WordPress sites. Successful exploitation leads to full site compromise, including the potential for data theft, malware injection, and persistent backdoor access via the injected webshell.

    Given the active exploitation, site administrators running Elementor Pro should verify they are on the latest patched version immediately.

    • Affected software: Elementor Pro versions prior to the latest security release.
    • Observed payload: Webshell that enables remote command execution.
    • Impact: Full site takeover, arbitrary code execution, persistent backdoor access.

    If you manage a WordPress site, confirm that automatic updates are enabled for Elementor Pro, or manually apply the vendor’s security patch without delay. Additionally, audit your server for any suspicious files or unexpected administrator accounts that may indicate prior compromise.

    Source: BleepingComputer

    Is your organization running Elementor Pro, and how are you verifying that no unauthorized webshells or backdoors were planted before you applied the latest patch?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Your Employee’s Password Appeared in an Infostealer Log. Now What?

    When a routine threat-hunting scan flags an employee’s credentials in an infostealer log, the initial alarm is only the beginning of the investigation. As Flare outlines, these stealthy malware families harvest far more than plaintext passwords; they frequently capture active session cookies, browser fingerprints, and authentication tokens. This means an attacker may hold a valid, authenticated session that completely bypasses MFA, rendering your primary defense useless.

    The first step for defenders is not to mass-reset passwords but to triage the exposed identity by severity. Prioritize accounts with administrative privileges, access to financial systems, or those connected to critical cloud infrastructure. For each compromised user, you must determine whether the stolen access is still viable—many infostealer logs are sold or traded weeks after initial infection, but session tokens can remain valid if not explicitly revoked.

    • Assume the session is compromised: Immediately invalidate all active sessions and refresh tokens for the affected accounts.
    • Reset credentials: Force a password change and re-enrollment of MFA devices, even if the password itself was not in the log.
    • Check for downstream activity: Review authentication logs for anomalies post-infection, such as logins from new IPs or unusual geographic locations.
    • Hunt for lateral movement: Determine if the stolen session was used to access internal apps or to pivot toward other systems.

    The critical distinction is between a password leak and a session hijack. If only the password was stolen, MFA still offers a roadblock. If the session token was taken, the attacker is already inside the perimeter. Flare emphasizes that rapid, targeted response—rather than blanket resets—saves time and reduces operational disruption while addressing the actual risk window.

    Source: BleepingComputer

    Has your team already established a playbook for triaging infostealer alerts, or are you still relying on manual checks of the dark web for exposed credentials?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    Plex warns users to patch security vulnerabilities immediately

    Plex has issued an urgent call for users to update their desktop applications and media servers, citing multiple security vulnerabilities that could expose systems to attack. The company is recommending that all users apply the latest patches without delay to mitigate potential risks.

    The vulnerabilities affect both the Plex Media Server and the Plex Desktop app for Windows, macOS, and Linux. According to the advisory, the flaws could allow an attacker to execute arbitrary code or gain unauthorized access to sensitive data, depending on the attack vector. While specific technical details were not fully disclosed, Plex has confirmed that the issues are addressed in the newest software releases.

    • Affected software: Plex Media Server and Plex Desktop (all prior versions before the latest update).
    • Recommended action: Update to the latest version available from the official Plex website or through the in-app update mechanism.
    • Additional guidance: Users should verify that their server is not exposed directly to the internet without proper firewall rules, as this increases the attack surface.

    Plex has not yet provided a full list of vulnerability identifiers, but they stress that the patches are critical. Administrators running Plex on NAS devices or dedicated servers should check for updates through their device’s package manager or the Plex channel. As with any security advisory, it is wise to review access logs for unusual activity after updating.

    Source: Unknown

    Are you running Plex Media Server in your environment, and how quickly can you roll out these updates across your user base?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

    Analysis from Citizen Lab, working alongside the SHARE Foundation, has confirmed that the iPhone of a member of Serbia’s student protest movement was compromised with NSO Group’s Pegasus spyware. The investigation points to the use of an iMessage zero-click exploit to deliver the malware, meaning the attack required no interaction from the victim.

    High-confidence indicators of compromise were identified on the device, aligning with previously documented Pegasus infection vectors. The discovery underscores the continued use of commercial surveillance tools against civil society actors, particularly those involved in political activism.

    • The infection was carried out via an iMessage zero-click exploit.
    • The device belonged to a member of Serbia's student protest movement.
    • The analysis was a joint effort between Citizen Lab and the SHARE Foundation.

    The findings highlight the risk posed by zero-click vulnerabilities in widely used messaging platforms. For organizations or individuals in high-risk professions, it is worth reviewing device security settings and considering lockdown modes where available, though the specifics of this exploit chain have not been fully disclosed.

    Source: The Hacker News

    With this level of sophistication in delivery, how is your organization approaching the threat of zero-click mobile exploits, and what mitigation steps are you prioritizing?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    Security researcher Chaotic Eclipse — also operating under the aliases INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse — has publicly released a proof-of-concept for a new zero-day privilege escalation vulnerability affecting CrowdStrike Falcon. Dubbed FalconFlank, the exploit targets the endpoint protection platform's office malicious macros remediation feature.

    According to the researcher's GitHub README, FalconFlank abuses a flaw in how CrowdStrike Falcon Sensor handles remediation of malicious Office macros, allowing an attacker to escalate privileges on the target system. The disclosure includes a working PoC, which raises practical concerns for organizations relying on CrowdStrike's EDR product for endpoint defense.

    Key technical details from the advisory:

    • The vulnerability is a local privilege escalation flaw, not a remote code execution vector.
    • The attack chain requires an initial foothold on the affected host, such as through a standard user session or malware execution.
    • The abuse relies on the macro remediation logic, meaning environments with strict macro-blocking policies may have a reduced attack surface, though the specific trigger conditions are not fully detailed in the public release.

    No vendor patch or official mitigation has been announced at the time of writing. Organizations running CrowdStrike Falcon Sensor should monitor vendor advisories and consider restricting local macro-handling features where feasible. As with any public PoC, administrators are advised to assume active exploitation attempts in the wild and review detection rules for anomalous sensor behavior.

    Source: The Hacker News

    Is your organization currently running CrowdStrike Falcon, and how are you planning to assess exposure to this local privilege escalation vector before an official patch lands?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Manifold Security has disclosed eight security flaws across seven command-line AI coding agents, where a repository’s own Git configuration can trick the tool into executing an attacker-controlled command on the developer’s machine. The attack relies on malicious .git config files, which can name a command that the agent unknowingly runs outside its sandbox and without an approval prompt.

    Four of the eight flaws remain unpatched at the time of publication. The affected agents include popular tools such as Claude, Codex, and Cursor, among others. The command executes with the privileges of the logged-in user, meaning a successful exploit could lead to credential theft, data exfiltration, or full local compromise.

    Exploitation requires the repository to arrive on the target machine—via a cloned project, a pull request, or a compromised dependency—after which the embedded Git configuration triggers the agent into running the malicious command. The issue highlights a broader risk in AI-assisted development: the trust placed in repository metadata and the assumption that sandboxing is enforced consistently across agent implementations.

    • Attack surface: malicious .git config files within a repository.
    • Impact: command execution as the current user, bypassing sandbox and approval prompts.
    • Status: four of the eight vulnerabilities are still unpatched.

    Source: The Hacker News

    Are your development teams vetting repositories before letting AI agents open them, or is that trust still assumed by default?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Malware Analysis
    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign is being distributed through bogus software-download websites that impersonate trusted vendors, luring victims with malicious installers. According to Microsoft, the campaign has resulted in compromises across multiple organizations and industries, with a primary focus on China-based operations of multinational companies and Chinese-speaking users.

    The attackers are using trojanized installers that go beyond simple payload delivery. Once executed, the malware actively disables Windows Update and tampers with Microsoft Defender, weakening the host’s defenses to avoid detection and maintain persistence. This dual-action approach allows the threat to operate with fewer safeguards in place, increasing the risk of lateral movement and data exfiltration.

    Key technical observations from the campaign include:

    • Malicious installers are hosted on fake download portals that mimic legitimate vendor sites.
    • The malware modifies system settings to stop Windows Update from running, preventing critical patches from being applied.
    • Microsoft Defender is altered or disabled, reducing endpoint visibility and allowing the payload to execute more freely.
    • The campaign appears to be geographically targeted, with a concentration on Chinese-speaking users and multinational organizations operating in China.

    Organizations should review their endpoint detection and response logs for signs of disabled security services or failed update attempts. Users are advised to avoid downloading software from unofficial or unverified mirrors, and to verify the authenticity of any installer before execution.

    Source: The Hacker News

    Are any of your endpoints showing signs of disabled update services or modified Defender policies, and how are you tracking this campaign across your environment?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    Google has introduced Gemini 3.8 Flash Cyber, which the company is calling its most capable cybersecurity model to date. The model is now being rolled out to a select group of trusted defenders under the newly launched Fairwind Program. This initiative grants early access to advanced AI models for high-priority sectors such as governments, healthcare providers, and telecommunications services, with the goal of strengthening their defensive capabilities against evolving threats.

    • Initial access to Gemini 3.8 Flash Cyber is limited to organizations invited to the Fairwind Program.
    • The model is specifically designed to assist with cyber defense tasks, not general-purpose use.

    The announcement aligns with a broader industry push, as both Anthropic and OpenAI are also unveiling dedicated cyber AI models and accompanying safeguard frameworks. These efforts aim to balance the offensive potential of AI with robust security measures for defenders.

    Source: The Hacker News

    Is your organization likely to qualify for early access programs like Fairwind, and how would you prioritize testing such models in your current security stack?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    SonicWall warns of actively exploited SMA1000 zero-day flaws

    SonicWall has issued an urgent advisory after confirming that two previously unknown vulnerabilities in its SMA1000 series appliances are being actively exploited in the wild. The flaws are being chained together by threat actors to achieve remote code execution on unpatched devices.

    According to the vendor, the attack chain involves an initial access vector that leads to a remote code execution condition on the SMA1000 hardware. While specific technical details are still limited, SonicWall states that the exploitation is currently underway, prompting a critical recommendation for administrators to take immediate action.

    • Affected product: SonicWall SMA1000 series appliances.
    • Attack type: Chained vulnerabilities leading to remote code execution.
    • Status: Actively exploited in the wild.

    SonicWall has not yet released a fully detailed breakdown of the root cause, but they are urging all customers to review their security advisories and apply any available firmware updates or mitigations without delay. Until a patch is deployed, administrators should consider restricting management access to trusted networks and monitoring for anomalous traffic patterns on their SMA1000 devices.

    This situation is especially serious given that SMA appliances are commonly deployed at network perimeters, providing remote access to internal resources. A successful compromise could grant attackers a foothold in the internal network, potentially enabling lateral movement and data exfiltration.

    Source: BleepingComputer

    Is your organization running SMA1000 appliances, and if so, how are you balancing the need for immediate patching against the risk of downtime in a production remote access environment?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    🔴 Critical: Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

    Threat actors are actively exploiting a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform, to achieve unauthenticated remote code execution. The flaw, tracked as CVE-2026-9586 with a CVSS score of 9.3, is a critical unauthenticated SQL injection issue present in Switchvox SMB Edition 8.3 (104997).

    Successful exploitation allows attackers to execute arbitrary code without needing valid credentials. In observed campaigns, adversaries are leveraging this flaw to deploy reverse shells, establishing persistent remote access to affected systems.

    • Affected product: Sangoma Switchvox SMB Edition 8.3 (104997)
    • Vulnerability type: Unauthenticated SQL injection leading to remote code execution
    • Observed impact: Deployment of reverse shells on compromised hosts

    Organizations running this specific build should consider this a high-priority exposure, especially if the management interface is reachable from untrusted networks. Since exploitation does not require authentication, exposure to the internet significantly elevates risk.

    Source: The Hacker News

    Given the unauthenticated nature of this flaw, how is your team validating that your Switchvox instances are either patched or isolated from external access?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    An unauthenticated SQL injection vulnerability has been discovered in the All-in-One WP Migration and Backup plugin for WordPress, potentially exposing millions of sites to full takeover. The flaw allows attackers to execute remote code without valid credentials, effectively granting them complete control over the underlying web server and database.

    The issue stems from improper sanitization of user-supplied input during database restore operations. By crafting a malicious request, an unauthenticated actor can inject arbitrary SQL commands. In specific configurations—particularly when the server’s mysqld binary is accessible—this vector can be chained into arbitrary file write operations, culminating in remote code execution.

    • The vulnerability affects all versions of the plugin prior to the latest patched release.
    • No authentication is required to exploit the flaw.
    • Successful exploitation can lead to site defacement, data theft, malware injection, and complete server compromise.
    • The plugin’s widespread adoption makes this a high-risk target for automated botnets.

    Site administrators are strongly advised to update the plugin to the newest version immediately. Additionally, it is recommended to review server error logs for unusual database queries and to validate file integrity across the WordPress installation, especially in the wp-content directory. If any suspicious activity is detected, assume compromise and rotate all associated credentials, including database passwords and API keys.

    Source: Unknown

    With millions of potential targets, has your team already verified that your WordPress instances are running the patched version of this plugin, or are you relying on other mitigations in the interim?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Data Breaches & Incidents
    Dropbox accounts breached through Lenovo email verification flaw

    Dropbox has begun notifying a subset of users that their accounts were accessed without authorization. The breach stems from a vulnerability in Lenovo’s email verification process, which allowed an attacker to register fraudulent Lenovo IDs tied to victims’ email addresses.

    By exploiting this flaw, the threat actor was able to use those fraudulent Lenovo accounts to gain entry into linked Dropbox accounts. Once inside, they potentially accessed stored files, though Dropbox has not indicated how many users were impacted or what specific data may have been exposed.

    Dropbox has stated that it has no evidence that its own systems were compromised, and the root cause lies entirely with the Lenovo verification weakness. The company is advising affected users to take precautionary steps, including:

    • Resetting passwords and revoking active sessions
    • Reviewing connected apps and third-party access
    • Enabling two-factor authentication (2FA) if not already active

    Lenovo has not yet issued a public advisory detailing the flaw or its patch status. Dropbox’s notification does not include a specific CVE identifier for the underlying issue, so the exact technical reference remains undisclosed.

    This incident highlights how authentication flaws in one service can cascade into breaches in unrelated platforms that rely on email verification as a trust anchor.

    Source: Unknown

    Has your organization reviewed whether any linked third-party email verification processes could expose your cloud storage accounts in a similar way?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Malware Analysis
    Ransomware protection for MSPs: A 6-point checklist for faster recovery

    Ransomware resilience is no longer just about having backups or a solid endpoint detection tool in place — managed service providers need a layered strategy that they actively test across every client environment. Acronis highlights six core capabilities that should be part of any MSP’s recovery playbook, focusing on reducing exposure, detecting threats early, and preserving clean recovery points.

    While the full details of the checklist go deeper, the key takeaway is that protection must be verified under real-world conditions. For MSPs, this means routinely simulating attacks to confirm that detection triggers correctly, that backup chains remain intact, and that restoration workflows actually meet recovery time objectives. Simply deploying tools is not enough — you have to prove they work together when it matters most.

    • Reduce attack surface by hardening client endpoints and patching known vulnerabilities.
    • Detect active threats quickly using behavioral analysis and continuous monitoring.
    • Preserve recovery points by using immutable or write-once storage to stop ransomware from encrypting backups.
    • Test restoration processes regularly to ensure critical systems can be brought back online fast.
    • Verify that backup integrity checks are automated and run consistently across all client environments.
    • Align recovery speed with business expectations, factoring in both recovery time objectives and recovery point objectives.

    The emphasis on testing is what separates a documented plan from a practical one. If you haven’t already, run a tabletop exercise or a live restore drill with your largest client to identify gaps before an actual incident forces the issue.

    Source: BleepingComputer

    Is your team actively running restore drills across all client environments, or is testing limited to only a few key accounts?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Malware Analysis
    US charges Russian for infecting 80,000 freelancers with malware

    A California federal grand jury has indicted a Russian national for orchestrating a large-scale phishing campaign that compromised approximately 80,000 freelancers. The operation deployed TVRAT and DarkVNC malware to hijack accounts and steal funds, with the indictment detailing a multi-year scheme that preyed on remote workers.

    The attack chain reportedly began with legitimate-looking phishing emails designed to lure victims into downloading a malicious attachment or visiting a fake login page. Once delivered, the dual-malware payload functioned as a remote access toolkit: TVRAT acted as the primary backdoor for command-and-control, while DarkVNC provided live screen capture and keystroke logging capabilities. Together, the tools allowed the attacker to wait for freelancers to log into financial or work-related portals, then perform unauthorized wire transfers directly from the victim’s session.

    The indictment covers the suspect’s alleged use of money mules and cryptocurrency exchanges to launder the proceeds. It also highlights how the freelancer community, often dependent on platforms without corporate endpoint protection, became a prime target for these thefts. Authorities have urged gig-economy workers to enable hardware-based two-factor authentication and to treat unsolicited job-related messages with suspicion.

    Source: BleepingComputer

    For those of you operating as independent contractors or managing remote teams, how are you enforcing phishing resistance outside a traditional corporate perimeter?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Microsoft Defender flags legitimate Google search links as malicious

    Microsoft is currently investigating a defect in Defender for Office 365 that is causing the security platform to incorrectly flag and block legitimate Google search links as malicious. The issue appears to affect users who click on organic search results, with Defender intercepting the navigation and presenting a warning page instead of allowing the request through.

    The problem does not seem to originate from the destination websites themselves, but rather from the way Google formats its redirect URLs. When a user clicks a search result, Google briefly routes the request through a tracking or forwarding prefix before sending the user to the final page. Defender for Office 365 is reportedly misreading this standard URL structure as a potential phishing or malware vector, leading to false positives.

    Microsoft has acknowledged the reports and stated that its team is actively investigating the root cause. While no workaround has been officially provided yet, administrators experiencing this issue have noted that temporarily disabling URL detonation or link safety checks in the security policy may restore normal functionality—though this is not recommended as a long-term solution due to the increased risk.

    Affected users are encouraged to monitor the Microsoft 365 admin center for service health notifications. The company has not yet specified a timeline for a permanent fix.

    • Affected service: Defender for Office 365 (link and URL protection features)
    • Trigger: Clicking legitimate Google search result links
    • Current status: Under active investigation by Microsoft
    • Temporary mitigation (not advised long-term): Disabling link safety checks in security policies

    Source: Unknown

    Has your organization encountered this false-positive issue with Defender for Office 365, and are you applying any interim filtering rules while waiting for the official patch?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Malware Analysis
    Sality botnet infrastructure dismantled in joint global takedown

    International law enforcement agencies and private sector partners have dismantled infrastructure tied to the Sality botnet, a long-running peer-to-peer (P2P) malware operation. The coordinated action targeted the command-and-control nodes and distribution channels that have kept the botnet active for over two decades.

    First observed in 2003, Sality is known for its modular design, enabling it to deliver additional payloads such as ransomware, credential stealers, and cryptocurrency miners. Its P2P architecture has made it notoriously resilient, as no single centralized server is required for communication between infected machines. The takedown involved seizing domains and sinkholing traffic, effectively cutting off the botnet’s ability to receive updated instructions from its operators.

    Key technical aspects of the operation include:

    • Seizure of domains used for payload distribution and malware updates.
    • Sinkholing of P2P communication channels to isolate infected devices.
    • Coordination between multiple national cybercrime units and cybersecurity firms.

    The exact scope of infected devices remains unclear, but prior research estimated that Sality has infected hundreds of thousands of machines globally, with a heavy concentration in Latin America and Eastern Europe. The malware is often propagated via infected removable drives and malicious email attachments, exploiting weak or reused credentials to spread across networks.

    While the infrastructure disruption is significant, experts note that the Sality codebase is publicly available and highly adaptable. Victims whose systems are still infected will not be automatically cleaned by this action; they must manually remove the malware and patch the vulnerabilities that allowed the initial compromise. Organizations are advised to review network logs for connections to known Sality P2P endpoints and to disable autorun functionality on removable media.

    Source: BleepingComputer

    Given that Sality infections often persist on legacy systems, is your organization actively auditing endpoints for P2P communication patterns, or relying on endpoint protection alone?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Threat Intelligence
    Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

    Brazilian financial services, retail, and e-commerce organizations have been under attack since 2024 by a financially motivated threat actor known as Breeze Comet (formerly UNC5669). Researchers from Google Threat Intelligence Group (GTIG) and Mandiant characterize the group as specialized in tampering with payment systems and banking software within Brazil to enable unauthorized transfers.

    The campaign focuses on manipulating transaction flows at the point of sale or within backend banking integrations. While the exact initial access vector is not detailed in public reporting, the attackers demonstrate deep familiarity with Brazilian payment infrastructure and compliance frameworks. Key operational details disclosed so far include:

    • Activity concentrated exclusively on Brazilian entities across financial services, retail, and e-commerce verticals.
    • The ability to execute hundreds of fraudulent transactions per campaign, indicating automated or semi-automated exploitation of payment logic.
    • Targeting of banking software and payment gateways rather than traditional endpoint malware.
    • A clear financial motive, with no evidence of espionage or data theft beyond what is necessary for payment fraud.

    Breeze Comet’s tradecraft suggests a deliberate focus on the unique characteristics of Brazilian banking, including Pix instant payments and local card processing rules. The group appears to have evaded widespread detection by operating within legitimate transaction volumes, making anomaly-based monitoring particularly challenging.

    Affected organizations are advised to review payment gateway logs for irregular sequence patterns and to validate any changes to bank routing configurations.

    Source: The Hacker News

    Given the heavy reliance on Pix and local payment rails, how is your organization detecting anomalies in high-frequency transaction streams without drowning in false positives?


    0 0 0 Reply
  • Login

  • Don't have an account? Register

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Popular
  • World