TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the s… Continue reading TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Posted in Uncategorized

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted… Continue reading New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Posted in Uncategorized

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.

MIT CSAIL researchers Daniël Trujillo and… Continue reading New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

Posted in Uncategorized

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.

This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent ins… Continue reading ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Posted in Uncategorized

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains.

Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet ap… Continue reading CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Posted in Uncategorized

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address.

Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users’ privacy by routing… Continue reading Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Posted in Uncategorized

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.

We observe… Continue reading AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

Posted in Uncategorized

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Ora… Continue reading Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Posted in Uncategorized