CISA has added a security flaw in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog following 792 reported exploit attempts. The vulnerability is being actively exploited, putting affected organizations at risk. Administrators should apply patches or mitigations immediately.
A new campaign uses ClickFix social engineering tactics to trick macOS users into installing malware that steals sensitive data, including crypto wallet credentials. The attack can drain digital assets from compromised wallets, posing a serious risk to cryptocurrency users. This highlights the expanding threat landscape beyond Windows-focused malware.
Attackers are using vishing (voice phishing) campaigns targeting employees' personal mobile phones to gain access to corporate SaaS accounts. By spoofing trusted entities, they trick victims into revealing credentials or multi-factor authentication codes. This matters because personal devices often lack corporate security controls, creating a vulnerable entry point for data breaches.
Attackers used adversary-in-the-middle phishing to hijack Microsoft 365 accounts, bypassing multi-factor authentication and intercepting payroll and finance-related emails. The campaign targeted specific users to enable wire fraud and business email compromise. This underscores the risk of AitM attacks against common cloud email services.
U.S. Immigration and Customs Enforcement has purchased access to credit card records, enabling the agency to review financial transactions. The arrangement raises significant privacy concerns about warrantless government surveillance of personal spending data. This signals an expansion of data-driven enforcement tactics by the agency.
A Canadian man has pleaded guilty to charges connected to extortion attacks against customers of the cloud data platform Snowflake. The scheme involved stealing corporate data and demanding ransom payments. His plea marks a key resolution in the federal investigation into a series of high-profile data breaches.
This roundup covers 30 security stories, highlighting a remote code execution flaw in Odysseus, a critical Samsung vulnerability enabling one-click device takeover, and ongoing controversy over an iCloud backdoor. These items matter as they detail severe, actively exploitable weaknesses in widely-used software and hardware.
Security researchers found vulnerabilities in agent frameworks from AWS, Google, and Vercel. The flaws let attackers trigger agent tools directly without running the underlying AI model, potentially bypassing safety controls. This matters because it exposes a new attack surface in AI-powered applications.
Security researchers found that certain Zbtlink router models ship with a hardcoded backdoor, allowing remote attackers to gain root shell access without any authentication. The flaw affects devices using a specific firmware version and could be exploited to hijack traffic or launch further attacks. Users are advised to check their router models and apply any available security updates immediately.