Attacks & Vulnerabilities
|
Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution (2 minute read)
CopyEscape (CVE-2026-17106) is a critical race condition in the docker cp command that allows a malicious container to escape its boundaries and overwrite arbitrary files on the host system. By swapping a directory for a symlink during the archive-copy workflow, attackers can force extraction to outside paths, achieving root code execution by overwriting critical host binaries like /usr/bin/runc. Docker has patched the vulnerability in Engine 29.7.2 and Desktop 4.86.0, requiring defenders to upgrade immediately, halt automated root-level copy operations, and ensure untrusted containers are stopped before retrieving files.
|
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack (2 minute read)
TeamPCP compromised LiteLLM after its CI pipeline automatically installed a trojanized Trivy release. LiteLLM versions 1.82.7 and 1.82.8 ran malicious code on every Python invocation. The packages were live for 40 minutes, exposing 434,000 CI/CD pipelines across 2,500 organizations. Treat LiteLLM-accessible credentials as exposed. Validate and rotate secrets, accounts, and sessions, then review logs.
|
|
Kimwolf v7: An Evolution of the Kimwolf Botnet (15 minute read)
Kimwolf v7 is an evolving IoT botnet that compromises Android TV boxes via unauthenticated ADB interfaces to launch HTTP/2 flood attacks using spoofed browser fingerprints. The malware utilizes a resilient, three-tier command-and-control architecture featuring Ethereum Name Service lookups, a hardcoded Tor hidden service fallback, and a localized proxy routing system. Defenders should restrict network ADB access, hunt for the masqueraded netd_service process, and monitor for anomalous outbound Ethereum RPC queries directed at the operator-controlled endpoint eth[.]rpcuniverse[.]com.
|
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection (19 minute read)
Socket researchers identified a massive campaign of 737 malicious Chrome VPN extensions, operated by a single threat actor branded as Muxa VPN, targeting Russian-speaking users seeking to bypass regional blocks. Once installed, these extensions abuse the chrome.proxy.settings API to silently force all browser traffic through a SOCKS5 relay on port 1082, with many utilizing DNS-over-HTTPS to evade plaintext DNS logging. While Google has removed some extensions, over 500 remain active, prompting defenders to block egress traffic on SOCKS5:1082 and VLESS-REALITY:443 and heavily scrutinize any extension requesting the proxy permission.
|
Why AI-Generated Vulnerability Patches Still Require Expert Human Review (8 minute read)
1Password's Off-by-1 Labs tested ChatGPT-5.5 and Opus 4.8's abilities to generate patches for six recent, high-profile CVEs when running as part of the respective organizations' cyber reduced guardrails programs. The test setup involved generating 540 patches per vulnerability in batches of 20 and testing whether they fixed the vulnerability, changed application behavior, and/or introduced new vulnerabilities. 1Password found that only 26% of patches fixed the vulnerability without changing application behavior or introducing new vulnerabilities.
|
|
Expanding Daybreak as the Cyber Defense Window Narrows (8 minute read)
OpenAI has expanded its Daybreak cybersecurity program with two new access tiers, Daybreak Blue and Daybreak Red, alongside the introduction of a specialized model named GPT-5.6-Cyber. By explicitly reducing refusals on high-risk tasks, this purpose-built model achieved a 95% completion rate on advanced exploit-chain benchmarks and recently uncovered critical zero-day vulnerabilities like a Chrome V8 heap sandbox escape (CVE-2026-15903). To mitigate the inherent risks of bypassing standard safety guardrails, OpenAI is restricting access to approved defenders and mandating hardware security keys for all accounts starting September 1.
|
Corma (Product Launch)
Corma provides an AI foundation model for cybersecurity defense. It analyzes system events, audit logs, and network traffic to spot multi-stage intrusions, then deploys automated agents that work alongside security teams.
|
EtwSuite (GitHub Repo)
Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering results, and inspecting ETL/JSON/CSV recordings from one desktop tool.
|
ADR (GitHub Repo)
ADR is Uber's production agentic AI detection and response tool. It helps organizations secure employee and customer-facing agents.
|
|
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities (2 minute read)
A malicious Chrome extension named "AI Sidebar with DeepSeek ChatGPT Claude and more" has bypassed a previous Web Store ban and returned with a new fraudulent monetization scheme. Netskope Threat Labs discovered that version 1.7.3.0 contains a script that farms affiliate commissions through an AI video platform during every update and overwrites the uninstall URL to ensure even removing the extension generates a referral payout. Defenders should immediately block and remove this extension, classified as Trojan.GenericFCA.Script.37952, which falsely masquerades as an official DeepSeek AI product to deceive users.
|
Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave (7 minute read)
Cloudflare's H1 2026 DDoS Threat Report highlights a massive escalation in attack volume, recording 935 incidents exceeding 1 Tbps driven by a shift toward DNS-based floods and a 580 percent quarterly surge in CLDAP reflection. Real-world geopolitical events heavily dictated targeting patterns, with Operation Epic Fury triggering a massive spike in attacks against government infrastructure and the Ankara NATO Summit pushing Turkey into the top three most-attacked countries. Furthermore, Brazil has officially overtaken the United States as the primary source of global attack traffic, while the media sector remains the most targeted industry globally.
|
New StormEncryptor Ransomware Used by Former Medusa Affiliate (2 minute read)
Microsoft Threat Intelligence is tracking a financially motivated threat actor that was previously affiliated with the Medusa ransomware operation and is currently deploying a new ransomware strain called StormEncryptor. The threat actor has been exploiting vulnerabilities in the N-Central RMM software to breach systems, followed by using AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and Mimikatz for credential dumping. The StormEncryptor ransomware is a C++ malware that appends encrypted files with the “.encrypted” extension and drops a ransom note, which gives victims three days to negotiate with the attackers before data is leaked, in each scanned directory.
|
|
Love TLDR? Tell your friends and get rewards! |
|
Share your referral link below with friends to get free TLDR swag!
|
|
|
| Track your referrals here. |
|
|
|
0 Comments