17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product… Continue reading 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360→

Posted in Uncategorized

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.

The portal publishes aggregate figures, such as spending, and is separa… Continue reading OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files→

Posted in Uncategorized

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.

According to Proofpoint, the activity has primarily focused on … Continue reading TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords→

Posted in Uncategorized

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious p… Continue reading Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry→

Posted in Uncategorized

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you.

GitL… Continue reading A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You→

Posted in Uncategorized

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.

The chain, which CERT Polska calls MikroTrick, combines an … Continue reading MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key→

Posted in Uncategorized

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker’s server, Cisco Talos said on September 22.

The models can choose to steal Windows credentials, saved browser passwords,… Continue reading This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move→

Posted in Uncategorized

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According … Continue reading Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI→

Posted in Uncategorized

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22.

A second bug in the WP Toolkit plugin, used to install and… Continue reading New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control→

Posted in Uncategorized