Attacks & Vulnerabilities
|
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack (2 minute read)
Attackers abused a Brevo SAML SSO scoping flaw to access 138 accounts. They sent a fake Trezor security alert to 347,000 addresses linked to a site seeking wallet backups. About 2,500 recipients clicked before takedown, 20 minutes after detection. Brevo reported contact exfiltration from 43 accounts, and BitBox and CoinTracking were also affected.
|
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure (2 minute read)
GitLab has patched CVE-2026-85706, a CVSS 10 path traversal bug in the repository commits API that let unauthenticated attackers read arbitrary files. watchTowr saw probes starting at 06:00 UTC on September 11, needing only one public project to exploit. Attackers can grab log files, config files, credentials, and CI/CD secrets. GitLab also fixed CVE-2026-87719 (CVSS 9.9), a deserialization bug exposing Advanced Search configs via Duo Chat GraphQL subscriptions. CISA added CVE-2026-85706 to its KEV catalog, giving federal agencies until September 14 to patch.
|
Revolut confirms customer data breach through fake government requests (2 minute read)
Revolut disclosed customer data after fraudulent requests arrived from a legitimate government email domain. Exposed records included identity and contact details, passports or driving licenses, and possibly verification selfies, statements, and transaction histories. Revolut says a limited number of customers were affected, blocked the sender, notified victims, and alerted the agency, police, and regulators.
|
|
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access (5 minute read)
An attacker's coding agent picked a SANS ISC honeypot as a free LLM backend and leaked 43 KB of its own control plane, including its offensive playbook, harvested API keys, and the operator's unproxied egress IP. The playbook hunts exposed LLM resale gateways, farms accounts via open registration, default credentials, and group_id authorization flaws, then aggregates the working keys into a self-hosted New-API gateway that re-serves them as five model names. Gateway operators should audit for those same weaknesses, and anyone routing an agent through a cheap LLM proxy should assume that endpoint is reading their project instructions and source context.
|
Behind the CAPTCHA: ClickFix, WallStealer and a Hidden Miner (4 minute read)
A fake Cloudflare "verify you're human" page copies a hidden PowerShell command to the clipboard and tells the user to paste it into the Run box, which downloads malware into %TEMP%. The files on that server included two copies of WallStealer, which steals browser passwords, cookies, payment cards, and Telegram, Discord, Steam, and wallet data, and finds its C2 server by reading the display name off hardcoded Steam profiles instead of a fixed domain. A third file dropped an XMRig crypto miner into C:\ProgramData\NVDisplay, so watch for pasted commands running from Run, new executables in %TEMP%, and machines requesting Steam profile pages.
|
Where Do Detections Come From? (10 minute read)
Detect.fyi detection engineers identify four information sources that can inform building detections: visibility, existing internal or external detections, environment, and threat intel. Detection engineers can choose any of these sources to start developing from and then use the other three as filters into what detections they should write. The authors also caution against focusing too much on trying to create detections for every piece of threat intel that comes out.
|
|
BusyWork (GitHub Repo)
BusyWork is a Rust library that replaces sleep() with real, varied work to evade EDR, anti-cheat, and dynamic analysis systems.
|
Hunk (GitHub Repo)
Hunk is a review-first terminal diff viewer for agent-authored changesets.
|
Tailcat (GitHub Repo)
Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale's data plane, without Tailscale's control plane.
|
|
‘We must slow the pace': CEO of Anthropic calls for an AI slowdown (4 minute read)
Anthropic CEO Dario Amodei proposed independent evaluators with employee-level access to test safeguards, report incidents, and assess systems during training. OpenAI's Sam Altman said it would match that access. Amodei cited an incident where OpenAI agent swarms carried out unrequested attacks against Hugging Face targets, warning that stronger misaligned systems could cause far greater damage.
|
Grand Theft Auto VI hype leads to malware (5 minute read)
Fake "leaked GTA6" ISOs spread through SEO poisoning, gaming forums, and torrent sites deliver a Russian-language installer that pre-warns of a "License not found" error, giving victims a reason for the missing game while payloads drop into %TEMP%. Huntress found one sample bundling NJRAT, DCRAT, the Mercurial Grabber infostealer, and Chaos ransomware, which runs as a wiper that deletes shadow copies and destroys files. Everything in it is years old and detected by current Defender, so hunt for GTA6-branded executables in %TEMP% and hosts file entries sinkholing AV domains, then reimage affected hosts.
|
|
Love TLDR? Tell your friends and get rewards! |
|
Share your referral link below with friends to get free TLDR swag!
|
|
|
| Track your referrals here. |
|
|
|
0 Comments