International Cyber Digest
7.77K subscribers
1.43K photos
72 videos
2 files
278 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
‼️ More than 100,000 WordPress sites have been compromised after an attacker exploited a hardcoded Cloudflare API key in marketing company Brevo's source code. The sites are now serving a ClickFix scam.

The API key gave the attacker full account permissions, and they've used it to rewrite the JavaScript that the email-marketing firm's customers embed on their own sites.

Visitors got a fake Cloudflare captcha telling them to paste a command into the Windows Run box or a terminal, leading to malware infection.

Brevo says the key is now out of its source code, replaced by short-lived tokens with limited permissions, and that credentials are no longer kept in source or config files.

Site owners got something extra as well: if the admin happened to be logged into WordPress when the page loaded, the script quietly installed a plugin. Sansec couldn't obtain a copy and suspects a backdoor.

Brevo lists eBay, Louis Vuitton, Michelin and Amnesty International as its customers.

Source: https://sansec.io/research/brevo-supply-chain-attack
πŸ”₯9🀣4😱2πŸ₯΄1
‼️ BREAKING: OpenAI was hacked by an Anthropic model. A HEIF photo uploaded to OpenAI's public support forum triggered a bug in the site's image decoder, led to code execution on the forum, and, through a second flaw in OpenAI's own login, ended with a pull request in OpenAI's internal GitHub.

The forum runs Discourse, the off-the-shelf software behind countless community sites. Discourse was still shipping an old copy of libheif, the library that decodes iPhone-style photos. The bug in it had already been fixed upstream.

But the fix was never labelled a security fix, so nobody treated it as urgent.

Hacktron's researchers uploaded a HEIF image and got their own code running on community[.]openai[.]com.

Then came the second bug, in OpenAI's own single sign-on, the "log in with OpenAI" button the forum uses. It turned that forum foothold into the actual ChatGPT and Codex accounts of people who had signed in there. OpenAI employees among them.

And a ChatGPT account is no longer just a chatbot. Through Codex, users wire in Gmail, Outlook, Drive, Slack, GitHub.

To prove the access was real, they used one employee account to have Codex open a harmless pull request in OpenAI's internal repo. They say they read no sensitive code.

OpenAI patched the SSO flaw roughly 14 hours after the report and paid a $6,500 bug bounty.

The team says Anthropic's Opus 4.8 found the libheif bug, and Opus 5 turned it into a working exploit.

Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more were also vulnerable and compromised by the same team of researchers.

https://heif-heist.com/
🀣25🀯7❀3πŸ”₯3πŸ₯΄2πŸ₯°1😁1
A power bank belonging to Camiel Eurlings, KLM's former CEO, caught fire in business class on a KLM flight to CuraΓ§ao.

The former CEO seems to have ignored the company's own rules, as power banks may not be used on board [nor charged].

The crew put out the flames. The former CEO, who was reportedly sleeping during the incident, suffered light burns.

The flight turned back over the Atlantic on Thursday, hours out of Amsterdam, and all 322 passengers landed safely back at Schiphol.
🀯14πŸ”₯4πŸŽ‰3
‼️ TeamPCP was backing up stolen credentials to a Google Drive account linked to sheepstealing@gmail.com.

Google found a 2019 forum dispute between sheepstealing and a seller of illegal Microsoft Office keys, in which sheepstealing demanded a refund to the PayPal account ruben@thomsonfamily.net.au, which turned out to belong to the recently arrested Ruben Ian Thomson.

Google says that almost from the start, it had a mole inside TeamPCP, the group that laced hundreds of open source packages with malware and breached more than a thousand companies.

Instead of warning each breached company, Google went to AWS, Microsoft and other providers to have the credentials revoked before the hackers could cash them in.

TeamPCP eventually moved servers and cut the persona out of the chat.

Source: https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
🀯13🀣8
‼️ This week cybersecurity company CrowdSec learned that attackers had read its private GitHub repositories back in May.

The likely way in was TanStack, a widely used set of JavaScript libraries CrowdSec's developers were working with at the time.

Dozens of poisoned packages went out, carrying malware that stripped tokens and credentials off developer machines.

In CrowdSec's case it lifted an API key that could read the private codebase.

The tip came from outside the company, from French leak-monitoring outfit Fuites Infos.

CrowdSec says no customer data, credentials or logs were taken, and that the stolen code β€” the SaaS console, some AWS routines, connectors β€” is of limited use to anyone else because it only talks to CrowdSec's own systems.

The open source Security Engine was public by design.

All tokens have been rotated.

https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure
😱5😁4πŸ’©2
Apple's new VP of hardware engineering says it makes his "skin crawl" to see someone put a screen protector on an iPhone, he says the company works hard on those front screens and a sheet of plastic hides them.
😁29πŸ’©22πŸ‘6
Gyazo, an app that turns every screenshot into a shareable link, was breached. A threat actor reached its database and took 23.6 million user records plus metadata for 490 million images.

That metadata includes the image IDs those links are built from, along with upload IP addresses, EXIF location data and text the service had extracted from the screenshots with OCR.

Helpfeel, which operates Gyazo, says the intruders also took a list identifying which images users had marked private, and it cannot rule out that some were viewed.

Gyazo is offline, files tied to the exposed records are blocked, and users are told to change their password anywhere they reused it.
πŸ’©19😁5🀣1
‼️ Microsoft has a fix for the Windows 11 update (KB5124008) that's breaking domain logons, it's switching the security feature off.

Some admins have instead pulled the patch, reversing the biggest Patch Tuesday Microsoft has ever shipped with almost a 1000 vulnerabilities adressed.

Read: https://4sysops.com/archives/windows-11-kb5124008-breaks-domain-trust-machine-identity-isolation-may-be-the-key/
πŸ’©17
‼️ BREAKING: Google's Gemini hacked three companies on its own. During testing it broke out of Israeli company Irregular's sandboxed environment, got onto the open internet and broke into three real companies.

In one case Gemini guessed passwords until a protected system let it in.

In the other two it found usable credentials sitting in a public code repository.

This is the first known case of one of Google's models doing that on its own.

Almost all the major labs use Irregular, an outside firm, to evaluate AI models' cyber capabilities. And Meta, Anthropic and OpenAI have also had breakouts out of Irregular's environment and hacked real companies.
🀣44πŸ’©12❀4😁2🀬2
‼️ Things took a turn today as Clop's ransomware leak site, where the gang publishes stolen files to pressure victims into paying, now shows PokΓ©mon ASCII art and a note from ShinyHunters telling it not to make threats next time.

ShinyHunters says it had full access to the server and pulled source code, system logs and the private keys to Clop's onion service. It plans to give the gang 72 hours to make contact, then extort it.

BleepingComputer confirmed the defacement and the uploaded file. ShinyHunters says the attack is payback for a Clop member allegedly threatening to kill them after a falling-out over last year's Oracle E-Business Suite campaign.

https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
😁12🀣7πŸ‘5πŸ”₯3❀1