Attacks & Vulnerabilities
|
CareCloud Data Breach Impact Grows to 3.7 Million Individuals (1 minute read)
CareCloud detected a network intrusion after an electronic health-record disruption in March. Attackers accessed an AWS environment from March 10 to 16 and claimed database theft. Exposed data includes identity details, insurance and medical records, and payment-card data for a limited group. HHS now lists 3,756,469 affected people, up from roughly 350,000 in state filings.
|
Sakura Internet Hack Exposes Data of up to 1.36M Accounts (2 minute read)
Japanese cloud and data center provider Sakura Internet disclosed that hackers accessed its sales management system, exposing data of 1.36M users. Sakura detected the hack while investigating another incident involving unauthorized access to 538 accounts. Sakura is currently notifying customers and relevant authorities.
|
Hackers Compromise 14,500 Dahua Web Cameras in 35-Day Campaign (2 minute read)
Researchers at Hunt.io uncovered a hacking campaign that targeted Dahua IP cameras, mostly in Ukraine and Russia. Hunt.io discovered the campaign by finding a working directory on an HTTP server that the operators left unprotected. The threat actors compromised 12,234 cameras by brute-force scanning on TCP port 37777, 1,923 cameras by exploiting known vulnerabilities using a tool called p2pwn, and 283 cameras that were behind NAT using only serial numbers and SDK credentials embedded in Dahua applications.
|
|
Hacking Your Life With AI Can Get You Hacked (8 minute read)
Endor Labs found 14 critical and high-severity flaws across NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Airflow. Several described paths allowed unauthenticated remote code execution, prompt-driven code execution, sandbox escapes, command injection, or data theft. Flowise, Kestra, and Langflow exposed exploitable paths without sign-in under some configurations.
|
Breaking Secure Boot Without Breaking the Crypto (57 minute read)
A signature check alone doesn't prove a device is safe. This post breaks secure boot into four failure buckets: did the check run, did it cover the right bytes, was the signer authorized, and do those bytes still run at execution time? It walks through Qualcomm's PBL/XBL-SC/TME chain, Android Verified Boot, DICE key derivation, and RATS attestation roles. Real CVEs illustrate each bucket: CVE-2019-2278 let a rejected keystore still verify a boot image, CVE-2023-48425 chains an AVB failure into a full bypass on a retail Chromecast, and CVE-2021-1931 lets one signed image authorize a different one.
|
Your Benign Set Should Look Malicious (6 minute read)
When testing detections to establish a false positive rate, it is common to build a set of benign data that should not be flagged. However, often the benign set is too benign and leads to artificially deflated false positive rates because the traffic doesn't resemble data that could be malicious. Instead, organizations should draw upon their internal docs, examples, etc to find negatives that matter to the organization and build a benign set that includes those.
|
|
SecFiles (GitHub Repo)
Useful files for penetration tests, security assessments, bug bounty, and other security-related stuff.
|
Shazzer Teams: Collaborative Fuzzing (3 minute read)
Shazzer Teams lets security researchers pool browser resources on a private distributed fuzzing network separate from the public pool while sharing a common vector library. Owners manage membership through expiring, usage-limited invite links and role-based permissions, and any member's browser automatically joins the team's fuzzing pool when the Network page is open.
|
CipherRun (GitHub Repo)
CipherRun is a comprehensive, TLS/SSL scanner written in Rust. It combines protocol and cipher analysis, vulnerability testing, compliance checks, and certificate transparency monitoring in a single high-performance CLI and API-ready engine.
|
|
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 (5 minute read)
Ransom Busters emailed ransomware victims, seeking $20,000 to $60,000. It claimed access to ransomware servers and offered file recovery and deletion of stolen data. GuidePoint linked two incidents through shared tooling, a “Numlock!123” backdoor account, and hostname DESKTOP-BBETH6K. The activity may be a ransomware affiliate posing as a recovery service, but payments cannot verify data deletion.
|
China Directs State Agencies to Uninstall Custom Windows 10 Edition Over Security Concerns (2 minute read)
China's Ministry of State Security has ordered state-linked organizations to immediately uninstall the custom Windows 10 CMIT edition due to data security concerns regarding foreign software reliance. This sweeping directive abruptly accelerates the retirement of the operating system originally developed through a 2016 joint venture with Microsoft. The government had previously scheduled the highly modified software to remain in active use until February 2027.
|
|
MLflow Bug Actively Exploited to Steal Credentials (2 minute read)
Organizations running MLflow versions prior to 3.15.0 must urgently patch to mitigate an actively exploited Server-Side Request Forgery vulnerability (CVE-2026-64849) that allows unauthenticated attackers to steal cloud credentials via DNS rebinding and malicious webhook redirects.
|
I'm Worried About a Prompt Injection Worm (2 minute read)
A prompt-injection worm could exploit AI agents parsing external inputs, such as emails, to exfiltrate data and propagate through victims' communication channels, so organizations should map AI integrations, model access levels, and build AI-specific incident response plans.
|
|
Love TLDR? Tell your friends and get rewards! |
|
Share your referral link below with friends to get free TLDR swag!
|
|
|
| Track your referrals here. |
|
|
|
0 Comments