Attacks & Vulnerabilities
|
Aesto Healthcare Data Breach Impacts 9.5 Million People (2 minute read)
Aesto reported that unauthorized access to part of its AWS infrastructure exposed data tied to 9,540,683 people. The intrusion ran from about December 2 to December 18, 2025. Records may include medical, insurance, financial, and government ID data. Aesto confirmed affected files in May, notified clients in June, and offered 24 months of Experian IdentityWorks.
|
Recently Patched PaperCut Zero-Days Used in Data Theft Attacks (2 minute read)
PaperCut Software announced two new vulnerabilities that have been patched in its PaperCut NG and MF print management software. The vulnerabilities involve an authentication bypass vulnerability which can be chained with a separately disclosed vulnerability to achieve RCE. Threat intelligence firm Defused reports that the authentication bypass vulnerability is being exploited by attackers for data theft.
|
|
Can AI Create PLC Attacks? Yes, But It's Not That Easy Yet (8 minute read)
Forescout used an AI model to port an RCE exploit from a WAGO 750-852 PLC to a 750-831 PLC running the same vulnerable Nucleus FTP server (CVE-2021-31886). The AI needed constant human guidance: correcting false leads, supplying disassembly context, and running Ghidra scripts it wrote itself. The final exploit stage took 8 hours 32 minutes and cost $535.74 in API tokens. A follow-up attempt to build a C2 implant bricked the PLC. Once code execution worked, the AI wrote working ICMP and UDP payloads within minutes.
|
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams (11 minute read)
Threat actors are executing voice phishing campaigns by registering external .onmicrosoft[.]com tenants with fake help desk names, initiating Microsoft Teams chats, and escalating to calls to trick victims into launching remote management tools. Following initial access, the attackers deliver distinct payloads that include an obfuscated PowerShell RAT designed to disable AMSI via the amsiInitFailed flag, and a Python-based execution chain that attempts PetitPotam coercion against domain controllers over port 445. To mitigate this threat, organizations must restrict external Teams access by default, block the associated payload hash, and proactively hunt for rapid chat-to-call sequences originating from commercial VPN nodes.
|
|
Humanbound (GitHub Repo)
Open-source adversarial testing engine, SDK, and CLI for AI agents. Attack your agent the way real users and attackers will: live endpoints, multi-turn conversations, and tool abuse. Then turn every failure into a firewall rule. Runs locally or against the Humanbound Platform. No login required to start.
|
open-kritt (GitHub Repo)
open-kritt is an open-source, self-hosted vulnerability research platform that turns focused AI analysis into de-duplicated, ranked findings with configurable validation and enrichment.
|
Microburst (GitHub Repo)
MicroBurst includes functions and scripts that support Azure Services discovery, weak configuration auditing, and post-exploitation actions such as credential dumping. It is intended to be used during penetration tests where Azure is in use.
|
|
Love TLDR? Tell your friends and get rewards! |
|
Share your referral link below with friends to get free TLDR swag!
|
|
|
| Track your referrals here. |
|
|
|
0 Comments