Attacks & Vulnerabilities
|
Anthropic Warns Claude Users of Infostealer Malware Infections (1 minute read)
Anthropic warned affected Claude users that infostealers hijacked browser sessions and drained usage limits. The malware included Vidar, Lumma, StealC, RedLine, Acreed, and AMOS. Anthropic logged out compromised sessions, removed stored payment methods, and refunded identified unauthorized charges. Users should remove malware before re-adding payment details.
|
ShinyHunters Claims it Stole 284 Million Patient Records from McKesson (2 minute read)
McKesson detected an intrusion on August 25 tied to third-party apps in its Oncology & Multispecialty and Medical-Surgical units. ShinyHunters vished McKesson employees, hijacked Okta SSO accounts, then pulled roughly a terabyte from Salesforce and Snowflake over four days. The group demanded $55,236,150 with a 72-hour deadline, which McKesson didn't pay. Breached data includes 284 million records containing SSNs, birth dates, Medicaid info, medical record numbers, medication/allergy data, and employee records.
|
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication (3 minute read)
Unauthenticated attackers can drive ADB commands on Android devices connected to Microsoft's open-source UFO Desktop AgentOS through CVE-2026-73296, which affects versions up to v3.0.7 and has no official patch. Attackers can exploit this vulnerability to capture screenshots, extract UI hierarchy data, and tap, swipe, and text-entry actions on TCP 8020 and 8021 whenever operators follow the documented remote-deployment guidance and bind to 0.0.0.0. Users should restrict those ports to trusted hosts and front the services with TLS and an authenticated reverse proxy until the proposed UFO_MCP_API_KEY bearer-token fix merges.
|
|
Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities (12 minute read)
Researchers found an exposed Amsterdam server staging tools and stolen Philippine data. Custom scripts abused ownCloud CVE-2023-49105, impersonating known users through unsigned WebDAV URLs. The recovered data included reactor records, radiation-safety files, employee PII, travel documents, BitLocker keys, KeePass data, and AxCrypt files. Logs referenced roughly 9 GB taken from the nuclear agency. A naval contractor's WordPress site was breached through LiteSpeed Cache CVE-2024-28000 and XML-RPC password guessing. The server also hosted Sliver, Metasploit, Mettle, and a loader that fetched a second-stage payload.
|
When it Snows it Pours – Anatomy of a ServiceNow Red Team (19 minute read)
MDSec red-team engagements turned phished ServiceNow users, exposed MID config.xml files, and over-permissioned roles into tenant admin access. Roles including catalog_admin, import_admin, and sn_cmdb_editor enabled Glide-script execution or role chaining. Operators created hidden admin accounts, altered timestamps, removed login and role histories, and used scheduled jobs as SnowFall C2 callbacks. From the tenant, they enumerated incidents and attachments, extracted credentials, bypassed adaptive authentication, and executed commands on MID servers through JAR plugins or the ECC queue.
|
When the Source Attacks Back: Prompt Injection Is Coming for OSINT (20 minute read)
Security researcher Dekens has demonstrated how adversaries can manipulate AI-assisted OSINT investigations by planting hidden prompt injections within digital documents. Through a dedicated training lab, Dekens highlights techniques like pushing CSS div elements off-screen, embedding white-on-white text in PDFs, and hiding instructions in unformatted spreadsheet cells. While not yet observed in active campaigns, these invisible artifacts successfully steer language models toward false narratives without altering the visually rendered file. To defend against poisoned sources, investigators should hash original documents and independently extract text using tools like Apache Tika or Tesseract to compare against the visual output. Furthermore, analysts must strictly isolate AI models in read-only environments to prevent untrusted inputs from executing unauthorized actions.
|
|
EMBA (GitHub Repo)
EMBA is designed as the central firmware analysis and SBOM tool for penetration testers, product security teams, developers, and responsible product managers. It supports the complete security analysis process, starting with firmware extraction, doing static analysis and dynamic analysis via emulation, building the SBOM, and finally generating a web-based vulnerability report.
|
Introducing Adaptive Intelligence: Undermining the Economics of Every Bot Attack (10 minute read)
Cloudflare has launched Adaptive Intelligence, a bot detection engine designed to make evasion economically unviable for attackers by continuously retraining its models on live traffic. Rather than relying on deterministic rules, the engine utilizes non-deterministic signal weighting and delayed reactions to prevent threat actors from isolating and defeating specific defenses. This cross-temporal evaluation allows the system to detect slow credential-stuffing attacks distributed across residential proxies that would otherwise bypass standard rate limits. Enterprise customers can activate the continuous retraining component immediately by enabling "Auto Update Machine Learning" in their Bot Management dashboard, while advanced features such as disposable rule generation are still in development.
|
Cloudflare OS (GitHub Repo)
Cloudflare OS is an “operating system” for AI productivity that consists of an agent chat UI, a sandboxed application development environment for small personal apps, and security guardrails.
|
|
OEMpocalypse Now (2 minute read)
Calif researcher Lukas Maar has developed a universal exploitation strategy that elevates an unprivileged Android app to root across modern Samsung, Xiaomi, and Oppo devices. Rather than hunting for generic kernel or chipset vulnerabilities, Maar targeted the proprietary OEM software overlays, such as One UI and HyperOS, that span each vendor's entire device lineup. The exploit leverages a page use-after-free vulnerability mapped to a freed physical page. This reliable technique successfully bypasses KASLR, control-flow hijacking, and slab protections without modification across kernels 5.4 through 6.12. While this initial publication outlines the overarching methodology on locked bootloaders, Maar plans to release the specific exploit chains affecting July 2026 flagship devices like the Galaxy S26 Ultra in future installments.
|
Open-Source Post-Quantum Cryptography Serverless CA (4 minute read)
Paul Schwarzenberger updated his open-source serverless CA with support for ML-DSA post-quantum cryptography. CA private keys are generated and used within AWS KMS FIPS 140-3 HSMS. ML-DSA is still not universally supported by applications, so users should check compatibility before adopting.
|
How AI Builders Will Get Hacked (4 minute read)
Developers who are frequently building tools with AI should ensure that they have a continuously running system that maintains a list of publicly exposed systems and continuously probes for basic security properties. AI builders can consider using full harnesses to comprehensively test critical systems. With the velocity of AI development, losing track of dangling, public resources will become a key attack vector.
|
|
Love TLDR? Tell your friends and get rewards! |
|
Share your referral link below with friends to get free TLDR swag!
|
|
|
| Track your referrals here. |
|
|
|
0 Comments