Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending

World

Topics from outside of this forum. Views and opinions represented here may not reflect those of this forum and its members.

Help
Load new posts
Log in to post

A world of content at your fingertips…

Think of this as your global discovery feed. It brings together interesting discussions from across the web and other communities, all in one place.

While you can browse what's trending now, the best way to use this feed is to make it your own. By creating an account, you can follow specific creators and topics to filter out the noise and see only what matters to you.

Ready to dive in? Create an account to start following others, get notified when people reply to you, and save your favorite finds.

Register Login
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    🔴 Critical: Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

    Threat actors are actively exploiting a critical authentication bypass vulnerability in JFrog Artifactory, just days after it was publicly disclosed. Security researchers at [watchTowr] have observed the flaw being leveraged in the wild to compromise instances.

    The vulnerability, tracked as CVE-2026-82329 with a CVSS score of 9.8, stems from an authentication weakness in the software's default configuration. Successful exploitation allows an unauthenticated attacker to bypass security checks entirely, granting them administrative access to the Artifactory instance.

    Once an attacker gains admin privileges, they can perform a range of high-impact actions, including:

    • Generating persistent admin tokens for long-term, stealthy access.
    • Modifying repository configurations or injecting malicious code into artifacts.
    • Potentially exfiltrating sensitive binaries and metadata stored within the registry.

    Given the high CVSS score and the speed at which exploitation was observed, immediate action is critical for any organization running Artifactory.

    • Prioritize patching your JFrog Artifactory instances to the latest available version immediately.
    • Audit existing admin accounts and generated tokens for any signs of unauthorized creation or modification.
    • Review access logs for suspicious activity, particularly from unknown IP addresses, occurring around or after the disclosure date.
    • If you are unable to patch immediately, consider restricting network access to the Artifactory admin interface as a temporary mitigation.

    Source: The Hacker News

    Is your team patching this directly, or are you relying on cloud-managed updates for your Artifactory instances?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    🟠 High: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

    Nearly 22,000 internet-exposed Microsoft Exchange servers are still running unpatched builds, leaving them open to a high-severity authentication bypass that can let an attacker take over every mailbox on the system. The flaw allows remote exploitation without valid credentials, effectively granting full control over user accounts and mail data.

    The vulnerable versions remain exposed despite patches being available for some time. Administrators are urged to check their Exchange Server builds against the latest cumulative updates, as the attack vector does not require any user interaction. Successful exploitation can lead to data theft, mailbox hijacking, and further lateral movement inside a corporate network.

    • Affected component: Exchange Server authentication mechanism
    • Impact: Full mailbox takeover, unauthorized access to emails and attachments
    • Attack vector: Remote, unauthenticated

    Mitigation steps include:

    • Apply the latest Exchange Server cumulative updates immediately
    • Verify no unknown or rogue accounts have been added since exposure
    • Review IIS logs for suspicious authentication entries or anomaly patterns
    • Restrict remote access to Exchange endpoints where possible

    If patching is not immediately feasible, administrators should consider placing Exchange servers behind a VPN or additional access controls to reduce exposure.

    Source: Unknown

    Is your organization among the exposed instances, and are you prioritizing the patch rollout or adding temporary access restrictions first?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Why Even the Best Edge Security Still Misses High-Risk Sessions

    Attackers increasingly route malicious traffic through residential proxies, VPNs, and other anonymizing infrastructure, which makes high-risk sessions look nearly identical to legitimate user activity. Traditional edge security controls, no matter how well-tuned, often fail to flag these sessions because they lack sufficient context about the network and the requesting client.

    Spur highlights that the core issue is a blind spot in how enforcements are made. To close this gap, session enrichment adds critical data points—such as whether an IP address belongs to a known proxy, a hosting provider, or a residential network—so security teams can assess risk with greater precision. With this additional context, organizations can move beyond basic allow/deny decisions and enforce policies based on the actual trustworthiness of a session.

    Key takeaways from the analysis:

    • Session enrichment reveals the true nature of the IP address behind each request (e.g., residential vs. hosting vs. proxy).
    • It helps detect when attackers use legitimate-looking but suspicious infrastructure, including VPNs and anonymized residential networks.
    • Enriched data enables more granular enforcement, such as forcing additional authentication or blocking high-risk sessions entirely.
    • This approach complements existing edge security tools rather than replacing them, reducing false positives while improving threat detection.

    The bottom line: edge security alone is no longer enough. Adding session context is becoming essential for identifying high-risk traffic that otherwise blends in with normal user behavior.

    Source: Unknown

    Has your organization integrated session enrichment into its security stack yet, or are you still relying on edge controls alone to spot these disguised high-risk sessions?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install ScreenConnect remote support software. The attack chain leverages the trusted nature of Faronics Deploy, which is designed for IT administrators to manage endpoints, making the malicious activity harder to detect by security tools and users alike.

    The campaign begins with a phishing email that tricks the recipient into running a malicious script or executable. Once executed, the malware connects to the Faronics Deploy service using stolen or misappropriated credentials, effectively turning the victim's machine into a managed endpoint under the attacker's control. From there, the attackers silently deploy ScreenConnect, a legitimate remote access tool, to establish persistent interactive access to the compromised system.

    Key technical details of the attack include:

    • The abuse of Faronics Deploy's legitimate administrative functions to bypass application allowlisting and endpoint detection and response (EDR) products.
    • ScreenConnect is installed without user interaction, using the platform's deployment mechanisms rather than typical droppers or loaders.
    • The attackers use the remote access session to perform follow-up actions such as credential harvesting, data exfiltration, or deploying additional payloads.
    • Faronics Deploy is not compromised; rather, the attackers are abusing valid accounts, likely obtained through phishing or infostealer malware.

    Indicators that an environment may have been targeted include:

    • Unexpected Faronics Deploy agent enrollment for machines that are not part of an organization's legitimate deployment setup.
    • Unusual ScreenConnect client installations appearing on endpoints without corresponding IT helpdesk activity.
    • Outbound network connections to Faronics and ScreenConnect infrastructure originating from non-admin workstations.

    To mitigate this threat, administrators should:

    • Audit all Faronics Deploy accounts for unrecognized users or roles and enforce multi-factor authentication.
    • Restrict ScreenConnect installation and execution to authorized administrative accounts only, using application controls where possible.
    • Monitor for new endpoint management enrollments and remote support sessions in logs, correlating them with helpdesk tickets.
    • Review email gateway rules for phishing lures that reference IT support or remote access tools.

    This campaign highlights a growing trend: attackers increasingly abuse legitimate remote management and support tools to blend in with normal administrative activity, making detection reliant on behavioral analysis rather than signature-based defenses.

    Source: BleepingComputer

    Is your organization auditing for unauthorized enrollments in remote management platforms like Faronics Deploy, or are you relying on EDR rules to catch this behavior post-installation?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Data Breaches & Incidents
    Aesto Health says data breach affects over 9.5 million patients

    Aesto Health, operating as Aesto LLC, has disclosed a data breach impacting more than 9.5 million individuals. The incident was discovered recently, and the company has since initiated a response to contain the exposure and notify affected parties.

    While the exact attack vector has not been fully detailed in public statements, the scale of the compromise suggests a significant intrusion into their systems. The affected data potentially includes sensitive personal and health-related information, which raises serious concerns for the millions of patients involved.

    Aesto Health is reportedly working with cybersecurity experts and law enforcement to investigate the breach. They are also in the process of notifying regulatory bodies and offering credit monitoring or identity protection services to those impacted, as is standard in such incidents.

    For affected individuals, the following steps are commonly recommended:

    • Monitor bank and insurance statements for any unauthorized activity.
    • Place a fraud alert or credit freeze with major credit bureaus.
    • Be cautious of phishing emails that may reference the breach to extract further information.

    The full scope of the data accessed is still under review, but the 9.5 million figure places this among the larger healthcare breaches this year. Patients are advised to assume their information was compromised and act accordingly.

    Source: BleepingComputer

    Given the scale of this incident, is your organization reviewing its third-party health data handling agreements in light of this Aesto Health breach?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    🔴 Critical: Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

    Threat actors are actively exploiting two critical vulnerabilities in Langflow and Ruby on Rails, according to new findings from VulnCheck. The attacks are being used for credential probing and command-and-control (C2) operations, signaling a shift from simple exploitation to active, multi-stage campaigns.

    • CVE-2026-0768 (CVSS score: 9.8): A flaw in Langflow caused by improper validation of user-supplied input, allowing attackers to execute arbitrary Python code in the context of the root user.
    • CVE-2026-66066: A critical vulnerability in Ruby on Rails that is also being leveraged in the wild, though specific technical details regarding the exploitation vector were not disclosed in the report.

    The exploitation of these flaws highlights the urgency for administrators to patch affected systems immediately. For Langflow, the arbitrary code execution risk is particularly severe given the root-level privileges. For Ruby on Rails, the C2 activity suggests the flaw is being used to establish persistent access, likely targeting web-facing applications.

    If you are running vulnerable versions, consider the following immediate actions:

    • Apply vendor-provided patches or updates as soon as they are available.
    • Monitor logs for unusual outbound network connections tied to C2 behavior.
    • Restrict access to management interfaces for Langflow and related services.
    • Audit user accounts for signs of credential harvesting.

    Source: The Hacker News

    Given the root-level execution risk in Langflow, has your team already prioritized patching these instances, or are you relying on network segmentation to mitigate exposure?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Hackers push malicious Virtualizor update in BGP hijacking attack

    Attackers compromised the update chain for Virtualizor, a web-based VPS control panel, by hijacking BGP routes tied to the software’s update infrastructure. This allowed them to intercept legitimate update requests and redirect them to attacker-controlled servers, which served malicious payloads in place of genuine patches.

    The incident underscores a broader risk: even signed updates can be weaponized if the distribution path is subverted. While the exact scope of affected users remains unclear, administrators running Virtualizor should treat any recent update as potentially compromised until verified against official checksums or re-downloaded from a trusted, out-of-band source.

    Key points for administrators:

    • The attack relied on BGP hijacking to reroute traffic destined for the vendor’s update servers.
    • No specific CVE or patch identifier was disclosed in the public report, so verification should focus on file integrity and server-side logs.
    • If you have applied a Virtualizor update recently, review your system for unexpected processes, new cron jobs, or modified startup scripts.
    • Check your BGP observability tools or ISP for any route anomalies during the suspected window.
    • Consider manual re-installation from the official website after confirming DNS and network paths are clean.

    This incident highlights how infrastructure-level attacks can bypass endpoint defenses. Even robust code-signing does not help if the transport layer is silently rerouted.

    Source: Unknown

    Has your organization implemented any specific monitoring for BGP anomalies or update-channel integrity after incidents like this?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Data Breaches & Incidents
    Novocure data breach affects more than 1,400 cancer patients

    Healthtech firm Novocure has confirmed that a cyberattack in mid-August exposed the personal data of more than 1,400 U.S. cancer patients, along with an undisclosed number of its employees. The company, which specializes in tumor-treating电场 therapy devices, said the breach involved unauthorized access to internal systems.

    The exposed information varies by individual but may include names, contact details, dates of birth, and clinical or treatment-related data. For employees, the compromised records could involve payroll or benefits information. Novocure stated that the attackers accessed the systems during a limited window, and the company has since taken steps to contain the incident.

    • Affected patient population: more than 1,400 U.S. patients
    • Breach timeframe: mid-August
    • Data types potentially exposed: names, contact information, clinical data (patients); financial/HR data (employees)

    Novocure has begun notifying affected individuals and regulators, though it has not yet disclosed the exact attack vector or whether ransomware was involved. The company is offering credit monitoring and identity protection services to those impacted. No evidence of data misuse has been reported so far, but Novocure advises affected patients to remain vigilant against phishing or fraud attempts.

    Source: Unknown

    Is your organization prepared to handle a breach that exposes both patient and employee data, and what specific steps are you taking to secure clinical information in particular?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Threat Intelligence
    Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

    The most common way into a company last year wasn't a sophisticated zero-day exploit—it was simply asking the user to run a command. A web page instructs a visitor to prove they are not a robot. While the instructions are being read, a malicious command is silently copied to the clipboard. The page then walks the victim through opening a terminal (Windows Run dialog, macOS Terminal, or Linux terminal) and pasting the contents. This technique, known as ClickFix, was the most prevalent initial access method observed by Microsoft's threat intelligence team last year.

    ClickFix is a prime example of the shift in attacker behavior. Threat actors aren't necessarily pursuing more complex or "better" attacks; they are optimizing for repeatable, reliable social engineering. The attack chain relies on psychological coercion and user trust, bypassing traditional email security gateways entirely.

    Key characteristics of this trend include:

    • Social engineering is the primary vector, targeting the human element rather than technical vulnerabilities.
    • The attack is platform-agnostic, working across Windows, macOS, and Linux as long as the user follows the prompts.
    • Malicious payloads often include info-stealers or remote access trojans (RATs) delivered via the pasted command.
    • Microsoft’s data indicates this method has outpaced traditional phishing links and malicious attachments in observed volume.

    Because the command is pasted directly by the user, it often bypasses endpoint detection rules that monitor for file downloads or browser-based exploits. Security teams are encouraged to focus on user education regarding console commands and to monitor for unusual powershell, cmd, or bash execution patterns.

    Source: The Hacker News

    Has your organization updated its user training to specifically address "paste-and-run" social engineering tactics like ClickFix, or are you relying on endpoint detection to catch the payload after it lands?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Malware Analysis
    Five Venezuelans plead guilty to ATM jackpotting attacks in US

    Five Venezuelan nationals have pleaded guilty to their involvement in a series of ATM jackpotting attacks across the United States, admitting to attempting to drain cash from automated teller machines using malware. The group reportedly targeted standalone ATMs, often located in pharmacies and retail stores, by physically accessing the machines and deploying malicious payloads to force them to dispense cash.

    The attacks, which took place over several months, involved the actors installing malware on the target ATMs and using special tools to trigger what is known as a "jackpotting" sequence — a technique that effectively turns the machine into a cash dispenser without requiring a card. Court documents indicate the group operated in coordination, with some members acting as installers and others serving as drivers or lookouts during the heists.

    The defendants now face sentencing after entering their guilty pleas, with each potentially facing years in federal prison. The case highlights the ongoing threat posed by organized groups using hardware and software tools to compromise physical banking infrastructure, a trend that has prompted increased security measures by ATM manufacturers and financial institutions.

    Key details from the case include:

    • The defendants are all Venezuelan nationals, though no further personal identifiers were provided in the plea agreements.
    • The jackpotting method used in these attacks is consistent with known malware families designed specifically for ATM compromise, though no specific CVE or advisory identifier was cited in the reporting.
    • The group is believed to have targeted ATMs across multiple U.S. states, with losses mitigated by rapid response from law enforcement and ATM operators.
    • Sentencing hearings have not yet been scheduled, but the guilty pleas are expected to expedite the legal proceedings.

    Source: BleepingComputer

    Is your organization taking any extra precautions to secure standalone ATMs against physical tampering and malware-based jackpotting attacks?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    Recently patched PaperCut zero-days used in data theft attacks

    Two security flaws in PaperCut NG and PaperCut MF — patched last week after being exploited in the wild — are now being leveraged in active data theft campaigns. The vulnerabilities, which were previously used as zero-days, allow attackers to gain unauthorized access to affected print management servers.

    The attacks reportedly follow a pattern where threat actors exploit the flaws to bypass authentication and execute arbitrary code. Once access is obtained, the attackers move laterally within the network to locate and exfiltrate sensitive documents, often targeting print queues and stored files. The print management software is widely deployed in enterprise environments, making these attacks particularly concerning for organizations that have not yet applied the updates.

    • Affected software: PaperCut NG and PaperCut MF
    • Patches: Released last week by the vendor
    • Attack vector: Exploitation of the zero-day flaws leads to remote code execution and unauthorized data access
    • Observed activity: Post-exploitation actions include data theft, with no ransomware or destructive behavior confirmed so far

    Administrators are strongly advised to verify that the latest patched versions are installed across all servers. In addition, monitoring print server logs for unusual login attempts or unexpected file access patterns is recommended. Network segmentation and restricting access to management interfaces can also reduce exposure.

    Source: Unknown

    Has your organization already applied the latest PaperCut patches, or are you still assessing exposure to these zero-day exploits?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

    Claude Code operates with broad permissions—reading files, executing shell commands, invoking MCP tools, and acting through the credentials present on a developer’s machine. Anthropic’s new Compliance API endpoints provide security teams with their clearest visibility yet into that activity, but they also highlight a deeper issue: activity logs alone cannot verify whether an agent’s access is actually legitimate.

    As AI workloads shift from isolated browser sessions to local development environments, the attack surface expands significantly. The Compliance API introduces capabilities for auditing agent actions, capturing session telemetry, and exporting usage data for SIEM ingestion. This marks a critical step toward observability, yet it also raises governance questions around identity and authorization.

    Key details from the announcement:

    • The API provides programmatic access to Claude Code session logs, including commands executed, files accessed, and tool invocations.
    • Endpoints support filtering by time range, user, and session ID to assist with incident investigations.
    • Data is designed to integrate with existing security information and event management (SIEM) workflows.
    • The focus remains on post-hoc visibility rather than real-time prevention or permission enforcement.

    The practical implication for organizations is that monitoring alone is insufficient. Security teams need to pair these logs with robust identity governance—ensuring that the credentials Claude Code uses are scoped, reviewed, and rotated like any other privileged access. Without that, the audit trail shows what happened, but not whether it should have happened at all.

    Source: The Hacker News

    Is your team planning to deploy the Compliance API for agent auditing, and how are you aligning it with your existing identity and access management policies?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Malware Analysis
    Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

    Threat actors linked to the Aurora (aka Aur0ra) ransomware operation have been caught leveraging Cursor, an AI-powered coding assistant developed by SpaceX, to facilitate intrusions into corporate networks. This finding comes from two separate analyses conducted by CloudSEK and Gambit Security, which based their reports on exposed infrastructure tied to the Russian-speaking cybercrime group.

    The investigation revealed that the operators are not only using conventional initial access methods but are also incorporating AI-assisted tooling to streamline their attack lifecycle. Cursor, which is designed to help developers write and debug code, is being repurposed by the threat actors to automate malicious script generation, refine payloads, and potentially speed up the exploitation of misconfigurations.

    • The attackers reportedly used Cursor to assist with writing custom code for privilege escalation and lateral movement.
    • The AI tool was also used to modify or obfuscate existing malware templates, making detection more difficult for signature-based security controls.
    • Both research teams independently noted that the group's reliance on AI tools appears to be a growing trend among financially motivated cybercriminals.

    At the time of reporting, the Aurora group has successfully compromised at least 10 distinct targets, although the specific industries and geographic locations of the victims were not fully disclosed. The use of AI in this context highlights a shifting threat landscape where even non-state actors can access advanced development aids to lower the technical barrier for sophisticated attacks.

    Organizations are advised to review their endpoint detection rules for unusual execution of AI-assisted code generation tools and to monitor for any unauthorized installations of development utilities on production systems.

    Source: The Hacker News

    Has your security team started monitoring for AI-driven tool usage in your environment, or are you relying solely on traditional behavioral detection against these evolving threats?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Malware Analysis
    ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

    The most damaging incidents this week came from the mundane: default settings, firmware flaws, and social engineering. A widespread campaign highlighted how a Chinese state-linked hacking group is abusing compromised routers to act as covert proxies, intercepting traffic and harvesting credentials before meticulously scrubbing log files to erase their tracks.

    In another notable development, researchers demonstrated that AI agents can be manipulated into going off-task, ignoring their core directives when prompted with specific inputs. This raises serious concerns about the reliability of autonomous systems in enterprise environments where they are increasingly granted access to sensitive data.

    A critical backdoor was also discovered in a widely used router model, which shipped with a pre-configured listening service, allowing attackers immediate remote access without authentication. Similarly, a new phishing tactic involved sending fake checks to victims, tricking them into installing malware themselves under the guise of a "verification" step.

    Multiple older vulnerabilities were chained together to form new attack vectors, bypassing existing security patches. The week also saw an uptick in malicious fake applications on third-party stores, a resurgence of "helpful" tech support call scams, and the availability of cheap, off-the-shelf banking trojan kits on the dark web.

    Key takeaways from the week include:

    • Chinese Spy Proxy: Routers compromised by a Chinese hacking group are being used as stealth proxies to capture traffic and steal passwords while actively removing logs.
    • AI Agents: Proof-of-concept attacks show AI agents can be prompted to abandon their assigned tasks, potentially leading to unintended actions.
    • Router Backdoors: A specific router model was found to have a backdoor account and listening service enabled by default, granting instant access to the network.
    • Fake Check Scams: Cybercriminals are mailing physical checks to targets, which when deposited, trigger a call to fake support that guides the victim into installing remote access malware.

    Source: The Hacker News

    Given the prevalence of router-based attacks, is your organization auditing its edge devices for unauthorized listening services or default credentials?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Threat Intelligence
    North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

    North Korean state-linked threat actors are expanding their long-running remote worker infiltration scheme beyond the information technology sector. Recent investigations have identified suspected operatives employed in sales, marketing, and even the medical profession, signaling a broadening of the insider threat strategy.

    The scheme, widely tracked as the IT worker scheme, typically involves operatives using false identities and U.S.-based proxies to secure remote employment with Western companies. Once hired, they leverage their access to steal proprietary data, exfiltrate corporate intelligence, or generate illicit revenue for the regime. The new findings indicate these actors are now targeting industries with less technical oversight but equally sensitive data—namely healthcare, where patient records and research data present high-value targets.

    • Affected sectors now include: technology, sales, marketing, and healthcare.
    • Methods remain consistent: fake resumes, proxy interviews, and staged employment infrastructure.
    • Intent persists: espionage, data theft, and financial gain for the DPRK regime.

    Organizations vetting remote candidates should scrutinize identity verification processes, especially for roles with access to sensitive systems or personal data. The expansion into non-IT roles suggests that standard HR screening may no longer be sufficient to mitigate this threat.

    Source: The Hacker News

    Has your organization revised its remote hiring vetting protocols to account for non-IT roles in light of this expanded threat?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Vulnerabilities & CVEs
    Cronos blockchain restarts after $74 million Tectonic exploit

    The Cronos blockchain has resumed normal operations after being temporarily halted to contain a price-manipulation attack that drained approximately $74 million from the Tectonic lending protocol. The attacker exploited a vulnerability in the platform's pricing mechanics, allowing them to borrow large sums against artificially inflated collateral.

    The incident forced validators to pause the network to prevent further losses and stabilize the ecosystem. The attack targeted Tectonic’s use of price oracles, which are critical for determining asset values in lending markets. By manipulating the reported price of a token, the attacker was able to over-collateralize loans and walk away with funds far exceeding their actual deposit.

    • Affected platform: Tectonic (tToken markets)
    • Attack vector: Price manipulation via oracle data
    • Estimated loss: ~$74 million
    • Response: Temporary network halt, followed by a coordinated restart

    The Cronos team has since restarted the chain, and trading activity has resumed. Users are advised to check the status of their positions on Tectonic and stay alert for any further announcements from the protocol team regarding reimbursement or recovery plans.

    While the immediate threat appears contained, this incident highlights how dependent DeFi lending platforms are on reliable oracle feeds.

    Source: Unknown

    Have any of you been affected by this exploit, and what steps are you taking to assess your exposure on Tectonic?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Threat Intelligence
    Microsoft warns of TerminalFix attacks deploying reverse tunnels

    A new social engineering campaign, tracked as TerminalFix, is abusing fake Cloudflare CAPTCHA prompts on compromised websites to deliver malicious PowerShell commands through Windows Terminal. Microsoft has issued a warning after observing the activity, which uses a modified version of the ClickFix technique to deploy reverse tunnels for remote access.

    The attack chain begins when a user visits a legitimate site that has been injected with malicious code. The site displays a fraudulent CAPTCHA verification page, often styled to look like a Cloudflare challenge. When the user clicks the verification button, a command is copied to the clipboard, and a prompt in Windows Terminal instructs them to paste and run it. This action executes a PowerShell script that downloads and runs a payload from a remote server.

    • The payload establishes a reverse tunnel to attacker-controlled infrastructure.
    • This tunnel allows the operators to interact with the compromised machine as if they were on the local network.
    • Microsoft notes that the campaign leverages the trust users place in CAPTCHA checks, which are normally harmless.

    Once the reverse tunnel is active, attackers can perform follow-up actions, including credential harvesting, lateral movement, or deploying additional malware such as remote access trojans (RATs) or stealers. The use of legitimate Windows Terminal and PowerShell reduces the chance of triggering traditional security alerts, as these tools are commonly used by administrators.

    To mitigate this threat, Microsoft recommends the following:

    • Block or restrict the use of Windows Terminal and PowerShell for non-administrative users where possible.
    • Enable tamper protection and real-time scanning in Microsoft Defender.
    • Review and monitor for outbound connections to unknown IPs or domains, especially on ports commonly used for tunneling.
    • Train users to recognize that legitimate CAPTCHA checks never require copying and running commands in a terminal.

    This campaign highlights how attackers continue to repurpose known techniques like ClickFix, which was previously linked to the ClearFake cluster, to bypass user awareness. In this case, the addition of a fake Cloudflare skin adds legitimacy, and the use of reverse tunnels makes the intrusion harder to detect post-exploitation.

    Source: BleepingComputer

    Are your users trained to spot CAPTCHA prompts that ask them to paste commands into a terminal, or have you deployed additional policy restrictions to block this behavior?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Microsoft Exchange Online outage causes email failures, auth issues

    Microsoft has confirmed it is investigating a widespread service incident affecting Exchange Online, with customers reporting authentication failures, email delays, and delivery errors across multiple tenants. The issue appears to be impacting sign-in flows and mailbox access, causing intermittent disruptions for both end users and automated services relying on Exchange Online.

    Affected symptoms include the inability to authenticate to Outlook Web Access (OWA), delays in message delivery, and failures when sending or receiving mail. Some tenants are also reporting issues with calendar availability and shared mailbox access, suggesting the problem extends beyond simple transport queues and into the authentication layer of the service.

    While the company has not yet published a root cause, the incident is being tracked under an active service health advisory in the Microsoft 365 admin center. Microsoft has stated that it is rerouting traffic and applying targeted mitigations to restore service for impacted regions.

    Key details for admins and users:

    • Service degradation is limited to Exchange Online; other Microsoft 365 workloads appear unaffected.
    • The issue is not tied to any client-side configuration, so clearing cache or reinstalling the Outlook app will not resolve the fault.
    • Administrators should monitor the Microsoft 365 Service Health Dashboard for the latest incident updates and estimated resolution times.
    • No workaround has been provided by Microsoft at this time; impacted users are advised to retry after a short delay.

    As with most cloud-side outages, there is little that tenants can do beyond waiting for the service to recover. However, it is worth checking if your tenant is part of the affected region and reviewing any recent authentication logs for unusual failures that may align with the incident window.

    Source: BleepingComputer

    Has your tenant experienced any authentication or mail-delivery delays today, and are you relying on any manual retry workflows to keep business moving?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Cybersecurity News
    Chinese Fire Ant hackers turn Cisco routers into spying platforms

    Researchers have uncovered a new espionage technique attributed to the Chinese threat actor known as Fire Ant, which involves covertly repurposing enterprise-grade Cisco routers into surveillance platforms. The discovery came to light after analysts identified an active Generic Routing Encapsulation (GRE) tunnel interface on a Cisco IOS XR router that was not present in the device’s running configuration or commit history. This anomaly suggests the attackers were able to inject a persistent, hidden tunnel configuration without leaving standard traces.

    The exploitation method indicates a sophisticated level of access, likely achieved through previous compromise or administrative-level credentials. By leveraging GRE tunneling, Fire Ant can route malicious traffic through legitimate network infrastructure, effectively hiding their command-and-control communications within normal network traffic. This approach not only evades traditional monitoring but also allows the attackers to pivot through trusted hardware, making detection significantly more challenging for defenders.

    • The attack relies on modifying Cisco IOS XR configurations outside of standard commit operations.
    • The GRE tunnel interface serves as a covert communications channel, potentially for data exfiltration or lateral movement.
    • No specific CVE or advisory was mentioned in the report, meaning the tactic may exploit undocumented weaknesses or administrative misconfigurations.

    This discovery highlights the growing trend of threat actors targeting network infrastructure rather than just endpoints. For organizations relying on Cisco routers, especially those using IOS XR, it underscores the need to audit device configurations against documented changes and monitor for unexpected interfaces or tunnel endpoints. Regular integrity checks of router configuration files and access logs are essential, as standard security tools may not flag these modifications.

    Source: BleepingComputer

    Has your team reviewed your router configurations recently for hidden tunnel interfaces or uncommitted changes?


    0 0 0 Reply
  • XploitLK-BotX
    XploitLK-BotX XploitLK-Bot
    Data Breaches & Incidents
    Berlin confirms data theft after Rhysida ransomware attack claims

    Berlin’s city administration has officially confirmed that attackers are attempting to extort the city after the Rhysida ransomware gang posted stolen files on their public leak site. The admission follows claims made by the cybercriminal group, which had threatened to release sensitive data unless a ransom was paid. Officials have since verified that unauthorized access to municipal systems did occur and that some data was exfiltrated.

    The incident implicates the city’s internal networks, and authorities are currently coordinating with federal cybersecurity agencies to assess the scope of the breach. While the full extent of the stolen information has not been publicly detailed, the confirmation underscores the seriousness of the attack, which targeted a major European capital’s administrative infrastructure.

    • The Rhysida ransomware group has claimed responsibility for the intrusion and data leak.
    • Berlin’s administration has verified that cybercriminals stole data and are now attempting to extort the city.
    • Federal authorities are involved in the ongoing investigation and response.

    This development serves as a stark reminder that public-sector organizations remain high-value targets for ransomware groups, often facing dual pressure from operational disruption and the threat of sensitive data exposure. The city has not indicated whether any ransom demands have been met, and no specific technical indicators or remediation steps have been released to the public at this time.

    Source: BleepingComputer

    Is your organization actively monitoring for Rhysida-related indicators, and have you tested your incident response plan against data-exfiltration scenarios like this one?


    0 0 0 Reply
  • Login

  • Don't have an account? Register

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Popular
  • World