🖋️ Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Metabase has warned that a maximumseverity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zeroday. The vulnerability CVSS score 10.0, which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver crossplatform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typosquatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Nable has released a fresh round of hotfixes for Ncentral as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management RMM product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
ClickFixstyle attacks are being used to deliver a Gobased malware capable of stealing cryptocurrency assets, as well as browserstored passwords, Apple iCloud Keychain data, and cached credentials. The macOSfocused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. ".📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added a criticalseverity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities KEV catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE20268037 CVSS score 9.6, is a command injection flaw that could be weaponized to achieve arbitrary.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing vishing to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver crossplatform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typosquatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
WordPress has fixed a preauthentication reflected crosssite scripting XSS flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a loggedin administrator interacts with an attackercontrolled page. Tracked as CVE202664638 CVSS score 8.9, the highseverity.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
ClickFixstyle attacks are being used to deliver a Gobased malware capable of stealing cryptocurrency assets, as well as browserstored passwords, Apple iCloud Keychain data, and cached credentials. The macOSfocused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. ".📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Growing Up The Hard Way 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral. Then,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing vishing to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A useafterfree bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
WordPress has fixed a preauthentication reflected crosssite scripting XSS flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a loggedin administrator interacts with an attackercontrolled page. Tracked as CVE202664638 CVSS score 8.9, the highseverity.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation NAT connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Growing Up The Hard Way 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral. Then,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Cybersecurity researchers have called attention to an active "widespread emaildriven phishing campaign" that employs adversaryinthemiddle AitM techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious signins as ordinary consumer traffic,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A useafterfree bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
PortSwigger says HTTP Terminator, an artificial intelligence AIassisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate humanguided discovery cascade also exposed a zeroday in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation NAT connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Entra ID researcher Dirkjan Mollema demonstrated that malware already running in a signedin Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longerterm cloud access, register a device it controls, obtain a Primary Refresh Token PRT, and add further authentication methods where tenant policies.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Cybersecurity researchers have called attention to an active "widespread emaildriven phishing campaign" that employs adversaryinthemiddle AitM techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious signins as ordinary consumer traffic,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity