The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak.The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet.RoguePlanet has been described
via The Hacker News https://ift.tt/mU3WJna
via The Hacker News https://ift.tt/mU3WJna
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation."SAP Commerce Cloud allows an
via The Hacker News https://ift.tt/QZDjhci
via The Hacker News https://ift.tt/QZDjhci
Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 420 nuove vulnerabilità, di cui una di tipo 0-day.
via RSS Csirt Italia https://ift.tt/6D7vaKP
via RSS Csirt Italia https://ift.tt/6D7vaKP
ACN
Aggiornamenti Mensili Microsoft
Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 420 nuove vulnerabilità, di cui una di tipo 0-day.
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them.Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more
via The Hacker News https://ift.tt/WdxyXE9
via The Hacker News https://ift.tt/WdxyXE9
Rilevate molteplici vulnerabilità, tra cui una con gravità “critica” e 16 con gravità “alta”, in MongoDB Server e MongoDB Driver.
via RSS Csirt Italia https://ift.tt/IU4ywA3
via RSS Csirt Italia https://ift.tt/IU4ywA3
ACN
Rilevate vulnerabilità in prodotti MongoDB
Rilevate molteplici vulnerabilità, tra cui una con gravità “critica” e 16 con gravità “alta”, in MongoDB Server e MongoDB Driver.
Rilevate 5 nuove vulnerabilità con gravità “alta” in Vim, noto editor di testo avanzato. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di eseguire codice arbitrario sui sistemi interessati.
via RSS Csirt Italia https://ift.tt/fsuz0US
via RSS Csirt Italia https://ift.tt/fsuz0US
ACN
Rilevate vulnerabilità in Vim
Rilevate 5 nuove vulnerabilità con gravità “alta” in Vim, noto editor di testo avanzato. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di eseguire codice arbitrario sui sistemi interessati.
Disponibile un Proof of Concept (PoC) per lo sfruttamento della vulnerabilità identificata dalla CVE-2026-17106, già sanata dal vendor, che interessa Docker Desktop, applicazione sviluppata da Docker Inc. che fornisce un ambiente completo per eseguire e gestire container Docker su Windows e macOS.
via RSS Csirt Italia https://ift.tt/jzm4Seu
via RSS Csirt Italia https://ift.tt/jzm4Seu
ACN
Docker: PoC pubblico per lo sfruttamento della CVE-2026-17106
Disponibile un Proof of Concept (PoC) per lo sfruttamento della vulnerabilità identificata dalla CVE-2026-17106, già sanata dal vendor, che interessa Docker Desktop, applicazione sviluppata da Docker Inc. che fornisce un ambiente completo per eseguire e gestire…
Rilevato lo sfruttamento attivo della vulnerabilità CVE-2026-20349, che interessa i prodotti Cisco Secure Firewall Adaptive Security Appliance (ASA) e Cisco Secure Firewall Threat Defense (FTD), soluzioni utilizzate per la protezione delle reti e l'accesso remoto mediante VPN.
via RSS Csirt Italia https://ift.tt/OrNHWRQ
via RSS Csirt Italia https://ift.tt/OrNHWRQ
ACN
Rilevato sfruttamento di vulnerabilità in prodotti Cisco
Rilevato lo sfruttamento attivo della vulnerabilità CVE-2026-20349, che interessa i prodotti Cisco Secure Firewall Adaptive Security Appliance (ASA) e Cisco Secure Firewall Threat Defense (FTD), soluzioni utilizzate per la protezione delle reti e l'accesso…
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were
via The Hacker News https://ift.tt/ieCTyEa
via The Hacker News https://ift.tt/ieCTyEa
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation.The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could
via The Hacker News https://ift.tt/diTNgDB
via The Hacker News https://ift.tt/diTNgDB
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 7 con gravità “critica” e 27 con gravità “alta”, nei prodotti Commerce, Magento, ColdFusion, Campaign Classic, Lightroom Classic, Content Credentials Rust SDK, C2PA Tool, Content Credentials JS SDK.
via RSS Csirt Italia https://ift.tt/MbghVtm
via RSS Csirt Italia https://ift.tt/MbghVtm
ACN
Adobe: aggiornamenti di sicurezza
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 7 con gravità “critica” e 27 con gravità “alta”, nei prodotti Commerce, Magento, ColdFusion, Campaign Classic, Lightroom Classic, Content Credentials Rust SDK, C2PA…
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 5 nuove vulnerabilità di sicurezza con gravità “alta”.
via RSS Csirt Italia https://ift.tt/IaRkjY3
via RSS Csirt Italia https://ift.tt/IaRkjY3
ACN
Risolte vulnerabilità in Google Chrome
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 5 nuove vulnerabilità di sicurezza con gravità “alta”.
Sanata una vulnerabilità con gravità “critica” in Grafana MCP Server, componente utilizzato per l'integrazione tra sistemi di intelligenza artificiale e piattaforme Grafana. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato l'elusione dei meccanismi di sicurezza e l'accesso ad informazioni sensibili sui sistemi interessati.
via RSS Csirt Italia https://ift.tt/QdbRVZT
via RSS Csirt Italia https://ift.tt/QdbRVZT
ACN
Sanata vulnerabilità in Grafana MCP Server
Sanata una vulnerabilità con gravità “critica” in Grafana MCP Server, componente utilizzato per l'integrazione tra sistemi di intelligenza artificiale e piattaforme Grafana. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato…
Aggiornamenti di sicurezza Zoho sanano una vulnerabilità con gravità "alta", presente nei prodotti M365 Manager Plus e M365 Security Plus
via RSS Csirt Italia https://ift.tt/SwZa7Be
via RSS Csirt Italia https://ift.tt/SwZa7Be
ACN
Zoho: sanata vulnerabilità in prodotti M365
Aggiornamenti di sicurezza Zoho sanano una vulnerabilità con gravità "alta", presente nei prodotti M365 Manager Plus e M365 Security Plus
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none.According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness
via The Hacker News https://ift.tt/noSLsvA
via The Hacker News https://ift.tt/noSLsvA
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords.The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing,
via The Hacker News https://ift.tt/BrMV8s4
via The Hacker News https://ift.tt/BrMV8s4
SonicWall ha rilasciato aggiornamenti di sicurezza per sanare 8 vulnerabilità, di cui 2 con gravità “critica” e 4 con gravità "alta", che interessano i prodotti Email Security e GMS.
via RSS Csirt Italia https://ift.tt/cZbsMqi
via RSS Csirt Italia https://ift.tt/cZbsMqi
ACN
Risolte vulnerabilità in prodotti SonicWall
SonicWall ha rilasciato aggiornamenti di sicurezza per sanare 8 vulnerabilità, di cui 2 con gravità “critica” e 4 con gravità "alta", che interessano i prodotti Email Security e GMS.
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash_history" and collecting meaningful additional data. Our reader David commented that this can also be done quite well with Linux's kernel process accounting feature, and I think he is very right. I really like Linux process accounting for a number of reasons, so here is a quick introduction.Process accounting is a kernel feature. You will not see a specific process responsible for it. Instead, the "accton" command signals the kernel to start logging process data to a specific location (usually /var/log/account/pacct). Once a process terminates, the kernel will log respective details to the binary log file.1 - InstallationI don't think process accounting is enabled by default on any Linux system. It does add a little additional overhead, but some users may shy away from it because it requires additional disk writes to collect the information. Memory and other CPUs should not be significantly impacted by process accounting. On my not very busy Proxmox system, it uses about 50 MB/day of disk space. So nothing that should be noticeable for most systems.Installation usually comes down to installing the respective package for your distribution. On Debian based distributions, it is just
apt install acctThis will typically also configure the startup scripts, but it can't hurt to runsystemctl enable --now acctThat is it. Wait a little bit, and you will see the log. 2 - How to read the logsLogs are saved in a binary format. The "lastcomm" command can be used to display the log in a readable format. For example:ip6tables-save S root __ 0.00 secs Wed Aug 12 06:25
iptables-restor S root __ 0.00 secs Wed Aug 12 06:25
iptables-save S root __ 0.00 secs Wed Aug 12 06:25
check_ssh 100107 __ 0.00 secs Wed Aug 12 06:25
cron F 100000 __ 0.00 secs Wed Aug 12 06:25
sh S 100000 __ 0.00 secs Wed Aug 12 06:25
debian-sa1 100000 __ 0.00 secs Wed Aug 12 06:25These are a few lines from my Proxmox server. It logs the process name, Flags (S=super user, F=forked process, D=generated core dump, X=terminated by signal), User name (or ID), CPU execution time, and finally the timestamp at which the process was started. The output may be modified slightly depending on the command-line arguments used.3 - Remote LoggingUnlike most Linux logs, these logs are not created by syslog. However, you may still read them with syslog to forward them to a central log collector/SIEM. Syslog-ng for example include a "s_pacct" processor for process accounting logs. You enable it with this configuration:source s_pacct {
pacct(file("/var/log/account/pacct"));
};4 - Other useful toolsThe "sa" command can be used to easily extract summaries from accounting data. For example, a breakdown by CPU time used by different processes# sa -c | head -10
329063 100.00% 259245.37re 100.00% 70.29cp 100.00% 0avio 24320k
469 0.14% 55.38re 0.02% 52.65cp 74.90% 0avio 124752k ffmpeg
488 0.15% 5.43re 0.00% 4.57cp 6.51% 0avio 5338k apt-get
2820 0.86% 3.60re 0.00% 3.34cp 4.74% 0avio 13295k ceph
1231 0.37% 1.96re 0.00% 1.92cp 2.73% 0avio 1974k ps
312 0.09% 1907.83re 0.74% 1.36cp 1.93% 0avio 88176k named
7 0.00% 39483.07re 15.23% 0.76cp 1.08% 0avio 6348k systemd-journal
123 0.04% 34804.71re 13.43% 0.34cp 0.48% 0avio 20367k ***other*
8 0.00% 0.68re 0.00% 0.27cp 0.38% 0avio 3926k store
366 0.11% 0.58re 0.00% 0.26cp 0.36% 0avio 2235k dpkg-deb*5 - ContainersProcess accounting…A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure.The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66
via The Hacker News https://ift.tt/v7Is6qL
via The Hacker News https://ift.tt/v7Is6qL
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
via The Hacker News https://ift.tt/j6VqT0w
via The Hacker News https://ift.tt/j6VqT0w
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. The model I use for this testing is gemma4:e4b [2] using two sites to compare the data against VirusTotal and CyberGordon. The following questions were submitted to Gemma for information:Instructions:1. Determine if we should be concerned with the volumes or suspicious volumes match indicators of compromise (IoC) or tactics mentioned on the two external websites.
2. Provide a concise comparative analysis and recommendations for action to prevent actors/bots to successfully compromise the sensor.
3. Identify what type of malware family (Popular threat label) the top 3 files are associated with.
4. Highlight potential issues with the top 3 inbound hashes (files) downloaded by actors/bots logged in the sensor and which sites have the most information about this activity.Result from the LLM AnalysisComparative analysis from Gemma 4 :
As a cybersecurity analyst, I have analyzed the provided data stream concerning files downloaded by actors/bots to the Cowrie sensors.Analysis of Downloaded Hashes (Top 10 IoCs)MediaFindings and Analysis1. Volume vs. IoCs vs. Tactics
The sheer volume of these hashes (126, 110 events) is a major concern. High volumes do not automatically confirm malicious intent, but when coupled with the fact that they are *downloaded* from an interactive sensor like Cowrie, it indicates successful actor persistence and data exfiltration attempts.Indicators/TacticsIndicator of Compromise (IoC): The hashes themselves act as IoCs if they resolve to known malware families or C2 infrastructure components. Since the external sites provided no results, the focus must be on the *behavior*—the repeated transfer of these files.
Tactics (MITRE ATT&CK): This activity strongly suggests **Persistence**, **Command and Control (C2)** communication, and potentially **Lateral Movement/Exfiltration**. The actors are not merely querying the system; they are downloading specific files repeatedly.2. Comparative Analysis & Recommendations| Aspect | VirusTotal (VT) | CyberGordon (CG) | Conclusion / Action Recommendation |
| :--- | :--- | :--- | :--- |
| Data Depth | High-fidelity, integrated threat intelligence from multiple sources (AV engines). Best for direct identification. | Academic/Historical analysis engine. Useful for deep source tracking and niche observations. | VT is superior for immediate threat context; CG offers supporting research. |
| Reliability | Generally reliable, though sometimes slow or requires paid access for full fidelity. | Utility appears high but the provided output is generic (focusing on JS compatibility rather than results). | **Rely primarily on VT/Commercial Threat Feeds.** Do not treat lack of a result as "safe." |
| Missing Data | The provided snippet was boilerplate ("Please enable JavaScript"), meaning we missed vital IoC intelligence. | The provided snippet was generic browser/engine advice, offering no actionable threat intel. | **Critical Action:** Develop a structured workflow to *ensure* the results page is fully processed and captured for all 10 hashes. |Recommendations for Action (Preventing Compromise):1. Immediate Containment: Treat any machine connected through this sensor as compromised. Isolate the host and initiate forensic imaging immediately.
2. Mitigation at Sensor Level: Update Cowrie's logging and alerting capabilities to track file *execution* attempts, not just downloads. Implement stricter egress filtering on the network hosting the sensors.
3. Threat Hunting (Proactive): Utilize the Top 10 hashes to query internal Endpoint Detection and Response (EDR) solutions across the entire enterprise, searching for the hash signatures or file names appearing on any system *outside* of the sensor environment.
4. …
2. Provide a concise comparative analysis and recommendations for action to prevent actors/bots to successfully compromise the sensor.
3. Identify what type of malware family (Popular threat label) the top 3 files are associated with.
4. Highlight potential issues with the top 3 inbound hashes (files) downloaded by actors/bots logged in the sensor and which sites have the most information about this activity.Result from the LLM AnalysisComparative analysis from Gemma 4 :
As a cybersecurity analyst, I have analyzed the provided data stream concerning files downloaded by actors/bots to the Cowrie sensors.Analysis of Downloaded Hashes (Top 10 IoCs)MediaFindings and Analysis1. Volume vs. IoCs vs. Tactics
The sheer volume of these hashes (126, 110 events) is a major concern. High volumes do not automatically confirm malicious intent, but when coupled with the fact that they are *downloaded* from an interactive sensor like Cowrie, it indicates successful actor persistence and data exfiltration attempts.Indicators/TacticsIndicator of Compromise (IoC): The hashes themselves act as IoCs if they resolve to known malware families or C2 infrastructure components. Since the external sites provided no results, the focus must be on the *behavior*—the repeated transfer of these files.
Tactics (MITRE ATT&CK): This activity strongly suggests **Persistence**, **Command and Control (C2)** communication, and potentially **Lateral Movement/Exfiltration**. The actors are not merely querying the system; they are downloading specific files repeatedly.2. Comparative Analysis & Recommendations| Aspect | VirusTotal (VT) | CyberGordon (CG) | Conclusion / Action Recommendation |
| :--- | :--- | :--- | :--- |
| Data Depth | High-fidelity, integrated threat intelligence from multiple sources (AV engines). Best for direct identification. | Academic/Historical analysis engine. Useful for deep source tracking and niche observations. | VT is superior for immediate threat context; CG offers supporting research. |
| Reliability | Generally reliable, though sometimes slow or requires paid access for full fidelity. | Utility appears high but the provided output is generic (focusing on JS compatibility rather than results). | **Rely primarily on VT/Commercial Threat Feeds.** Do not treat lack of a result as "safe." |
| Missing Data | The provided snippet was boilerplate ("Please enable JavaScript"), meaning we missed vital IoC intelligence. | The provided snippet was generic browser/engine advice, offering no actionable threat intel. | **Critical Action:** Develop a structured workflow to *ensure* the results page is fully processed and captured for all 10 hashes. |Recommendations for Action (Preventing Compromise):1. Immediate Containment: Treat any machine connected through this sensor as compromised. Isolate the host and initiate forensic imaging immediately.
2. Mitigation at Sensor Level: Update Cowrie's logging and alerting capabilities to track file *execution* attempts, not just downloads. Implement stricter egress filtering on the network hosting the sensors.
3. Threat Hunting (Proactive): Utilize the Top 10 hashes to query internal Endpoint Detection and Response (EDR) solutions across the entire enterprise, searching for the hash signatures or file names appearing on any system *outside* of the sensor environment.
4. …
Ollama
gemma4
Gemma 4 models are designed to deliver frontier-level performance at each size. They are well-suited for reasoning, agentic workflows, coding, and multimodal understanding.