Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/
https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/
Microsoft News
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker…
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook
Trojan that contains a dynamic infection chain with a heavy anti-analysis loading component that can deploy two embedded payloads (worm, banker). The observed infection chain bundles a malicious MSI installer inside a ZIP file. These MSI installer packages are abusing a signed Logitech program called Logi AI Prompt Builder..:
https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
Trojan that contains a dynamic infection chain with a heavy anti-analysis loading component that can deploy two embedded payloads (worm, banker). The observed infection chain bundles a malicious MSI installer inside a ZIP file. These MSI installer packages are abusing a signed Logitech program called Logi AI Prompt Builder..:
https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
PamDOORa: Analyzing a New Linux PAM-Based Backdoor for Sale on the Dark Web
https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web
https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web
Ping, Payload, PowerShell: Active Exploitation of CVE-2026-22679 in Weaver E-cology
https://blog.vega.io/posts/cve-2026-22679-weaver-ecology-exploitation/
https://blog.vega.io/posts/cve-2026-22679-weaver-ecology-exploitation/
vega.io
Ping, Payload, PowerShell: Active Exploitation of CVE-2026-22679 in Weaver E-cology — Vega Blog
The Vega Threat Research team identified active exploitation of CVE-2026-22679, a critical unauthenticated RCE in Weaver E-cology, 14 days before public in-the-wild reporting. This report details real-world exploitation and post-compromise behavior.
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps
..The malware’s primary command-and-control channel has been migrated onto The Open Network (TON) using .adnl endpoints routed through an embedded local TON proxy..:
https://www.threatfabric.com/blogs/new-trickmo-variant-device-take-over-malware-targeting-banking-fintech-wallet-auth-app
..The malware’s primary command-and-control channel has been migrated onto The Open Network (TON) using .adnl endpoints routed through an embedded local TON proxy..:
https://www.threatfabric.com/blogs/new-trickmo-variant-device-take-over-malware-targeting-banking-fintech-wallet-auth-app
ThreatFabric
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps
Perseus is a new Device Takeover (DTO) malware family that specifically looks for user-generated content stored in note taking applications.
AppSecFest 2026 - В эту пятницу в Алматы, Farabi Hub
Будут экспертные эксперты, тимлиды, специалисты, представители IT-индустрии, AppSec/DevSecOps-практики, инженеры по безопасности.
+ будет открытое CTF-соревнование от команды mimicats – где можно пропробовать свои скиллы в реальных задачах по ИБ (максимум практики, никакой теории)
+ Воркшопы с живое общением на темы AppSec, DevSecOps, инженерной культуры, процессы, и даже факапы
• Начало: 15 мая, 09:00, Farabi Hub
Все спикеры заслуживают внимания, многих знаю лично, все детали здесь: appsecfest.kz
Будут экспертные эксперты, тимлиды, специалисты, представители IT-индустрии, AppSec/DevSecOps-практики, инженеры по безопасности.
+ будет открытое CTF-соревнование от команды mimicats – где можно пропробовать свои скиллы в реальных задачах по ИБ (максимум практики, никакой теории)
+ Воркшопы с живое общением на темы AppSec, DevSecOps, инженерной культуры, процессы, и даже факапы
• Начало: 15 мая, 09:00, Farabi Hub
Все спикеры заслуживают внимания, многих знаю лично, все детали здесь: appsecfest.kz
Dead.Letter (CVE-2026-45185) How XBOW Found an Unauthenticated RCE on Exim
https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim
https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
NGINX ngx_http_rewrite_module Heap-Based Buffer Overflow (Queries and Signatures Only)
An unauthenticated attacker can crash the NGINX worker process by sending crafted HTTP requests - CVE-2026-42945:
https://docs.vulncheck.com/initial-access/2026-05-15#cve-2026-42945-nginx-ngx_http_rewrite_module-heap-based-buffer-overflow-queries-and-signatures-only
An unauthenticated attacker can crash the NGINX worker process by sending crafted HTTP requests - CVE-2026-42945:
https://docs.vulncheck.com/initial-access/2026-05-15#cve-2026-42945-nginx-ngx_http_rewrite_module-heap-based-buffer-overflow-queries-and-signatures-only
Vulncheck
New exploits, detections, and more for ProFTPD, Ollama, WordPress, and TP-Link TL-WR940N routers. Queries and signatures for NGINX.…
CVE-2026-20182: Cisco SD-WAN Authentication Bypass via vHub (ASM Queries Only), CVE-2026-42945: NGINX ngx_http_rewrite_module Heap-Based Buffer Overflow (Queries and Signatures Only), CVE-2026-42167: ProFTPD mod_sql USER SQL Injection Pre-Auth RCE, CVE-2024…
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
⚡ DNS is not just about domains. It is about Trust.
Recent supply chain incidents are a strong reminder that modern attacks often start through tools and workflows developers already trust:
• npm packages and dependency updates
• compromised maintainer accounts
• VSCode extensions
• GitHub Actions workflows
• fake installers and update mechanisms
Several recent cases highlight this trend:
• Axios compromised on npm - malicious versions dropped a Remote Access Trojan >
• Compromised VSCode Nx Console >
• OpenAI TanStack npm supply chain attack >
• OpenAI Axios developer tool compromise >
• GitHub unauthorized access to internal repositories >
The key takeaway: supply chain attacks are becoming more relevant to every developer, engineering team, and company.
DNS security should not be treated as an optional layer.
It can provide visibility and control when malicious code attempts to:
• connect to C2 infrastructure
• reach phishing domains
• communicate with fake update servers
• exfiltrate data through suspicious endpoints
If malicious code has already entered the environment, visibility becomes critical...
At this point, the key questions are simple:
• Can you see where it is trying to connect?
• Can you understand whether that connection is expected?
• Can you react before the incident becomes bigger?
OpenBLD.net - Security starts earlier than incident response.
Watch yourself, your emails, your extensions, and your DNS. Peace ✌️
Recent supply chain incidents are a strong reminder that modern attacks often start through tools and workflows developers already trust:
• npm packages and dependency updates
• compromised maintainer accounts
• VSCode extensions
• GitHub Actions workflows
• fake installers and update mechanisms
Several recent cases highlight this trend:
• Axios compromised on npm - malicious versions dropped a Remote Access Trojan >
• Compromised VSCode Nx Console >
• OpenAI TanStack npm supply chain attack >
• OpenAI Axios developer tool compromise >
• GitHub unauthorized access to internal repositories >
The key takeaway: supply chain attacks are becoming more relevant to every developer, engineering team, and company.
DNS security should not be treated as an optional layer.
It can provide visibility and control when malicious code attempts to:
• connect to C2 infrastructure
• reach phishing domains
• communicate with fake update servers
• exfiltrate data through suspicious endpoints
If malicious code has already entered the environment, visibility becomes critical...
At this point, the key questions are simple:
• Can you see where it is trying to connect?
• Can you understand whether that connection is expected?
• Can you react before the incident becomes bigger?
OpenBLD.net - Security starts earlier than incident response.
Watch yourself, your emails, your extensions, and your DNS. Peace ✌️
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Bumblebee (from Perplexity)
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
https://github.com/perplexityai/bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
https://github.com/perplexityai/bumblebee
GitHub
GitHub - perplexityai/bumblebee: Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata…
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises. - perplexityai/bumblebee
Rokarolla : Android Banker with Complete Device Takeover Capabilities
https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
Zimperium
Rokarolla : Android Banker with Complete Device Takeover Capabilities
true
Crypto Clipper uses Tor and worm-like propagation for persistence and control
https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/
P.S. it work at current time, In the world of artificial intelligence and technological breakthrough)
https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/
P.S. it work at current time, In the world of artificial intelligence and technological breakthrough)
Microsoft News
Crypto Clipper uses Tor and worm-like propagation for persistence and control
Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent…
FortiBleed - Breach How 80,000+ Corporate= Firewalls Were Quietly Compromised
If your organization uses a Fortinet firewall or VPN product and appears in this dataset, treat your network perimeter as already compromised and act immediately. SOCRadar rates this campaign Critical..:
https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
If your organization uses a Fortinet firewall or VPN product and appears in this dataset, treat your network perimeter as already compromised and act immediately. SOCRadar rates this campaign Critical..:
https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/
Vishing actors target Entra passkey enrollment (mimics the Microsoft passkey enrollment)
The threat actor registers domains that incorporate the word passkey as part of a voice-enabled phishing (“vishing”) scheme. The threat actor then calls targeted users on the phone in an attempt to persuade them that they need to register a new passkey.:
https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/
The threat actor registers domains that incorporate the word passkey as part of a voice-enabled phishing (“vishing”) scheme. The threat actor then calls targeted users on the phone in an attempt to persuade them that they need to register a new passkey.:
https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/
Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting
https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas
https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas
ZeroBEC
Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 | ZeroBEC
ZeroBEC threat research on Forg365, a Kali365-class Microsoft 365 PhaaS that combines Telegram distribution, AI-assisted lure generation, device-auth phishing, AiTM routing, AntiBot evasion, token vaulting, and a Manifest V3 browser extension (ForgCookie)…
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left
mindgard.ai
Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard
The vulnerability nobody seems interested in fixing
Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm
www.stepsecurity.io
Compromised next Branch Pushes Malicious @asyncapi/generator, generator-helpers, and generator-components to npm - StepSecurity
On July 14, 2026 at 07:10 UTC, three packages in the AsyncAPI generator monorepo (@asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, and @asyncapi/generator-components@0.7.1) were published to npm carrying an obfuscated dropper that fires the moment…
ClickLock Stealer: Paste Once, Lose Everything
Upon execution of the ClickFix command, the malicious script shows a terminal-based loading animation mimicking Cloudflare progress bar with browser verification flow..:
https://www.group-ib.com/blog/clicklock-stealer-macos-malware/
Upon execution of the ClickFix command, the malicious script shows a terminal-based loading animation mimicking Cloudflare progress bar with browser verification flow..:
https://www.group-ib.com/blog/clicklock-stealer-macos-malware/
Group-IB
ClickLock Stealer: Paste Once, Lose Everything
Analysis of ClickLock, a modular macOS stealer delivered via ClickFix that uses fake dialogs, kill loops, and a GSocket backdoor to steal passwords, browser data, and crypto wallets.