Attacks & Vulnerabilities | Discord discloses data breach after hackers steal support tickets (3 minute read) Discord suffered a data breach on September 20. The Scattered Lapsus$ Hunters threat group compromised a third-party Zendesk customer service system, stealing personal data, including names, government IDs, partial payment information, and support communications from users who contacted Discord's support teams. The attackers demanded a ransom payment and threatened to leak the stolen data, which security experts warn could be valuable for solving cryptocurrency-related crimes, as many scammers use Discord without proper anonymization. Organizations should review their third-party vendor access controls, implement additional monitoring for customer service platforms, and ensure incident response procedures include immediate isolation of compromised third-party systems. | Hacking group claims theft of 1 billion records from Salesforce customer databases (3 minute read) A hacking group known by several names, including Scattered Spider and ShinyHunters, claims to have stolen approximately a billion records from companies using Salesforce cloud databases. The group is extorting victims with threats to leak stolen data unless ransoms are paid. Multiple major companies are affected. Salesforce denies any breach of its platform or vulnerabilities in its systems. | Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL (2 minute read) SORVEPOTEL is a self-propagating malware campaign targeting Brazilian users that spreads through WhatsApp by exploiting social trust and sending malicious ZIP file attachments disguised as receipts or health app files. The attack chain begins with phishing messages from compromised contacts, which leads victims to open Windows shortcut files that execute PowerShell scripts to download payloads from external servers and establish persistence via the Windows Startup folder. Once installed, the malware automatically detects active WhatsApp Web sessions and mass-distributes the malicious ZIP files to all contacts and groups, prioritizing rapid propagation over data theft and frequently resulting in account bans due to spam violations. | | Pointer leaks through pointer-keyed data structures (13 minute read) Google Project Zero demonstrated a novel technique to remotely leak memory addresses without memory safety violations by exploiting pointer-keyed data structures in Apple's NSKeyedArchiver serialization. The attack works by crafting specific NSDictionary objects with carefully chosen NSNumber keys to control hash bucket placement, then using the serialized ordering of an NSNull singleton (whose hash is its memory address) to determine its location in the shared cache. While theoretical and requiring a deserialize-reserialize attack surface, this technique demonstrates how pointer-based hashing in keyed data structures can leak addresses even without timing attacks. Organizations should audit serialization endpoints and consider using keyed hash functions instead of raw pointer addresses for object hashing. | Signal Protocol and Post-Quantum Ratchets (23 minute read) Signal's Sparse Post Quantum Ratchet (SPQR) is part of a new "Triple Ratchet" protocol that combines its existing Double Ratchet with quantum-resistant ML-KEM cryptography to protect against future quantum computing threats while maintaining forward secrecy and post-compromise security. The implementation uses erasure coding and state machines to efficiently transmit large ML-KEM keys (over 1,000 bytes) in small chunks, includes a graceful downgrade mechanism for backward compatibility during rollout, and employs formal verification using ProVerif and F* to ensure protocol correctness. Security professionals should note that this represents a practical approach to post-quantum migration, which preserves existing security guarantees while introducing quantum resistance. The protocol automatically upgrades conversations without requiring user intervention. | VED 2026: after CFI - data only (10 minute read) Modern kernel privilege escalation attacks have shifted from traditional control flow methods like ROP to more stealthy, stable data-only attacks that bypass Control Flow Integrity (CFI), prompting the development of advanced defense systems like VED (Vault Exploit Defense). Novel techniques, such as DirtyPipe, cred-jar heap spray, and pipe primitives, exploit weaknesses in kernel memory handling to corrupt authentication data or page buffers, directly overwriting critical structures, including credential jars and pipe buffers, while evading detection by typical CFI solutions. VED counters these threats through multiple integrity measures, including shadow data tracking, hash monitoring, slab poisoning, and specialized protections for core patterns and pipe buffers, aiming to detect stealthy modifications and strengthen kernel security against increasingly sophisticated data-centric exploits while minimizing performance impact. | | Gulp (GitHub Repo) Gulp is a Python-based incident response platform that accelerates security analysis through high-speed data ingestion from multiple sources, SIGMA rule querying across thousands of detection rules simultaneously, and collaborative investigation features with zoomable timelines for event visualization. The tool leverages OpenSearch and Elastic Common Scheme (ECS) formatting for compatibility while providing scalable multiprocessing capabilities that can grow with organizational needs. Security teams can use Gulp to ingest, query rapidly, and collaboratively analyze security events in a unified platform explicitly designed for incident response workflows. | Send Gmail end-to-end encrypted emails to anyone (3 minute read) Gmail's client-side encryption now allows users to send end-to-end encrypted emails to any email provider. External recipients receive a notification and access the message via a guest account, eliminating the need for key exchange or special software. Available for Enterprise Plus with Assured Controls, this feature must be enabled by administrators. It was rolled out on September 30. This feature simplifies cross-platform encrypted communication by removing key management and software barriers. | MokN (Product Launch) MokN provides identity protection based on honeypots, with ultra-realistic decoy access points, including VPNs and email servers, that replicate the organization's environment. If an attacker attempts to log in to one of these honeypots using a stolen identity, the security team is alerted and can take appropriate action. | | GreyNoise detects 500% surge in scans targeting Palo Alto Networks portals (2 minute read) GreyNoise detected a 500% surge in scanning activity targeting Palo Alto Networks login portals on October 3, with over 1,285 IP addresses (93% suspicious and 7% malicious) conducting coordinated reconnaissance that mirrors previous Cisco ASA scanning patterns and shares TLS fingerprints linked to Netherlands infrastructure, potentially signaling upcoming vulnerability disclosures since historical patterns show Palo Alto scan spikes often precede new flaw announcements within six weeks. | CometJacking: One Click Can Turn Perplexity's Comet AI Browser Into a Data Thief (2 minute read) CometJacking affects Perplexity's Comet AI browser by allowing attackers to use a malicious link to inject hidden prompts and steal sensitive user data, such as emails and calendars, by exploiting the browser's own access. Experts warn that this demonstrates the broader risks of AI-driven browsers and have urged stricter agent prompt security to prevent future data theft campaigns | How We're Making Application Security Smarter (3 minute read) Wealthsimple was faced with the common dilemma of having a small security team tasked with reviewing code written by a much larger engineering team in a highly regulated environment. It introduced Semgrep AI to create custom fixes for the specific code under review, augmenting its security team. Semgrep remembers previous decisions on findings and uses that information to auto-triage future findings | | | Love TLDR? Tell your friends and get rewards! | | Share your referral link below with friends to get free TLDR swag! | | | | Track your referrals here. | | Want to advertise in TLDR? 📰 If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us. Want to work at TLDR? 💼 Apply here or send a friend's resume to jobs@tldr.tech and get $1k if we hire them! If you have any comments or feedback, just respond to this email! Thanks for reading, Prasanna Gautam, Eric Fernandez & Sammy Tbeile | | | |
0 Comments