#zeroday — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.
-
Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild
Pulse ID: 6a9c93480062fd59fc51e7fe
Pulse Link: https://otx.alienvault.com/pulse/6a9c93480062fd59fc51e7fe
Pulse Author: cryptocti
Created: 2026-09-05 22:10:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti
-
Threat campaign Targeting Magento StyleSmuggler Zero-Day RCE Exploitation in the Wild
Pulse ID: 6a9c93a4d5f17d95c5d2e9cf
Pulse Link: https://otx.alienvault.com/pulse/6a9c93a4d5f17d95c5d2e9cf
Pulse Author: cryptocti
Created: 2026-09-05 22:11:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #cryptocti
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Indicators extracted from public reporting. Source: https://sansec.io/research/stylesmuggler
Pulse ID: 6a9c81d4bc0f1cbcf2e3262a
Pulse Link: https://otx.alienvault.com/pulse/6a9c81d4bc0f1cbcf2e3262a
Pulse Author: CyberHunter_NL
Created: 2026-09-05 20:55:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Magento #OTX #OpenThreatExchange #RCE #ZeroDay #bot #CyberHunter_NL
-
StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now.
#StyleSmuggler #Magento #AdobeCommerce #ZeroDay #RCE #eCommerceSecurity #Sansec #Infosec
-
Trezor Breach Exposes 67,000 US Customers' Data
A data breach at Trezor's shipping provider has compromised the personal info of 67,000 US customers, including names, emails, phone numbers, addresses, and order numbers. The breach, linked to a zero-day SQL injection vulnerability, has raised concerns about customer data security, but Trezor assures that its hardware wallets remain secure.
-
📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity
-
Update Chrome to the latest version immediately; the attackers already knew about this before you did.
Reward: You've received a Cracked Piston — cosmetic only, non-functional, much like your unpatched browser was.
#ZeroDay #Chrome #CyberSecurity #V8Engine #Vulnerability #PatchedOrPerish (2/2)
-
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
🚨🛡️ SIGINT // Cybersecurity Watch — 2026-09-05
OpenAI's Astra becomes first AI model to cross 'Critical' cyber threshold after finding zero-days on its own.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
#AI #CyberSecurity #ZeroDay #InfoSec -
📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046)
Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité. CVE-2026-85046 (CVSS : 8.8) est une faille de type confusion dans le moteur V8 (JavaScript/WebAssembly de Chrome). Elle permet à…
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-google-corrige-le-sixieme-zero-day-chrome-activement-exploite-en-2026-cve-2026-85046/
🌐 source : https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026.html
🟢 vérification factuelle haute
#Chrome #ZeroDay #Cyberveille -
CrowdStrike Zero-Day Exploit Grants SYSTEM Privileges on Windows Systems
A new zero-day exploit, dubbed FalconFlank, can grant attackers SYSTEM-level access to fully patched Windows machines protected by CrowdStrike Falcon, allowing them to spawn a command prompt with elevated privileges. This alarming vulnerability leverages CrowdStrike's own Office malicious macros remediation feature to perform a…
#Crowdstrike #ZeroDay #Windows #PrivilegeEscalation #FalconSensor
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
This is Chrome's sixth actively exploited zero-day of 2026, which we are required to describe as "on track." Compliance confirmed.
Update Chrome to version 152.0.7977.82 or later immediately, as that is the only action that will actually help you.
Reward: You've received the Malicious Compliance Badge. It confers no protection.
#Chrome #ZeroDay #V8 #CyberSecurity #Vulnerability #PatchedOrPerish (2/2)
-
Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
-
Google patched CVE-2026-85046, a V8 type confusion zero-day in Chrome confirmed exploited in the wild. It is the sixth actively exploited Chrome zero-day this year and enables remote arbitrary code execution via crafted web content. #ChromeSecurity #VulnerabilityManagement #ZeroDay
https://cyberworldops.eu/en/chrome-fixes-sixth-zero-day-of-2026-active-attacks-target-v8-engine
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
There is no unequip button.
Warning: This item is Soulbound to your infrastructure the moment threat actors find your exposed instance. Patch Langflow and restrict access to the custom component editor before reading the rest of this tooltip.
Reward: You've received the Cursed Relic of Arbitrary Execution. It cannot be traded, sold, or returned.
#Cybersecurity #RCE #Langflow #CVE #ZeroDay #AchievementUnlocked (2/2)
-
Google Patches Actively Exploited Chrome V8 Zero-Day Flaw
Google just patched a high-severity Chrome zero-day flaw that's being actively exploited - a type confusion vulnerability in V8 that could let hackers run malicious code inside the browser's sandbox. This critical update brings Chrome's version up to 152.0.7977.82, so make sure you've got the latest version installed!
-
Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
-
Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances
SonicWall's SMA 1000 appliances are under attack, thanks to two newly disclosed zero-day vulnerabilities - CVE-2026-83548 and CVE-2026-83549 - that can be chained together for a complete network compromise. Attackers are already exploiting these flaws in the wild, prompting urgent patching advice from the vendor and cybersecurity authorities.
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046).
#Chrome #ZeroDay #Vulnerability #Cybersecurity #CVE202685046
-
Security Researcher Exploits CrowdStrike Falcon with New Zero-Day Bug
A security researcher known as Nightmare Eclipse has made a stunning discovery, exploiting a zero-day bug in CrowdStrike's Falcon software and prompting the company to urge customers to disable a key Windows policy setting. This latest finding is part of a string of proof-of-concept exploits released by the…
#ZeroDay #CrowdstrikeFalcon #ProofofconceptExploits #NightmareEclipse #EmergingThreats
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
OpenAI recognized Astra as its first model possessing critical cybersecurity capabilities, capable of autonomously finding zero-day vulnerabilities.
#OpenAIAstra #CyberSecurity #ZeroDay #ArtificialIntelligence #InfoSec
-
Pegasus Spyware Targets Serbian Student Activist's iPhone
A Serbian student activist's iPhone was hacked with NSO Group's notorious Pegasus spyware through a clever zero-click exploit targeting Apple iMessage, according to a joint investigation by Citizen Lab and SHARE Foundation. This sneaky attack allowed the spyware to infect the device without the user even clicking on a link.
-
Researcher Exposes Privilege Escalation Flaw in CrowdStrike Falcon
A security researcher, known as Chaotic Eclipse, has uncovered a zero-day privilege escalation flaw in CrowdStrike Falcon, dubbed FalconFlank, which exploits the office malicious macros remediation feature. This vulnerability allows for a potentially devastating escalation of privileges, and a public proof-of-concept has…
#ZeroDay #PrivilegeEscalation #CrowdstrikeFalcon #Proofofconcept #EmergingThreats
-
A PaperCut zero-day (CVE-2026-81578, CVE-2026-82078) is exploited in the wild. Attackers run malicious SQL for RCE, and a Metasploit PoC is now public.
#PaperCut #CVE202682078 #ZeroDay #RCE #InfoSec #Metasploit #SQLi
-
AI napisało exploita na zero-day. Google go złapało, bo… był zbyt „grzeczny”
Google Threat Intelligence Group (GITG) wspólnie z ekipą Mandiant poinformowało o wykryciu pierwszego w historii exploita typu zero-day, który został stworzony przy wyraźnym wsparciu modelu językowego (LLM).
Hakerzy użyli sztucznej inteligencji, by uderzyć w popularne narzędzie administracyjne typu open-source i ominąć uwierzytelnianie dwuskładnikowe (2FA).
Zbyt pilny uczeń zdradza hakera
To, co w tej sprawie jest najbardziej fascynujące, to fakt, że sztuczna inteligencja „wsypała” swoich twórców przez… nadmierną staranność. Eksperci Google’a zidentyfikowali udział AI w tworzeniu złośliwego kodu po kilku specyficznych cechach, które nie występują w „tradycyjnym” malwarze (w sensie: tym tworzonym przez ludzi). Co zdradziło autorstwo AI?
- Podręcznikowy styl: skrypt w Pythonie był napisany niezwykle czysto, niemal w sposób akademicki.
- Nadgorliwe komentarze: kod zawierał mnóstwo edukacyjnych opisów modułów, co jest typowe dla odpowiedzi generowanych przez chatboty, a zbędne dla hakerów.
- „Halucynacje” w kodzie: AI dodało do skryptu zmyślone punktacje CVSS (system oceny groźności luki), których hakerzy nigdy by tam nie umieścili.
- Estetyka ponad wszystko: skrypt zawierał rozbudowane menu pomocy i klasy kolorowania tekstu w konsoli (ANSI color), co sugeruje, że haker poprosił AI o „ładny i profesjonalny program”.
Chiny i Korea Północna na „promptach”
Raport Google’a rzuca też światło na to, jak państwowe grupy hakerskie „jailbreakują” modele AI, by służyły im do brudnej roboty.
Chińska grupa UNC2814 stosuje technikę „persony”: każą sztucznej inteligencji wcielić się w rolę „starszego audytora bezpieczeństwa”, co pozwala ominąć filtry blokujące generowanie złośliwego kodu. Z kolei koreańska grupa APT45 zalewa modele tysiącami powtarzalnych zapytań o analizę znanych podatności (CVE), traktując AI jako darmowego stażystę do żmudnej roboty przy wyszukiwaniu luk w zabezpieczeniach.
Co to oznacza dla nas?
Nie doczekaliśmy się jeszcze „Terminatora”, który sam wymyśla broń masowej zagłady, ale jesteśmy świadkami narodzin ery „Script Kiddie 2.0”. AI po prostu bardzo obniża próg wejścia w zaawansowaną cyberprzestępczość. Zamiast lat nauki pisania exploitów, wystarczy sprytny zestaw promptów i odrobina wiedzy, by „uzbroić” nową lukę w systemie.
Dobra wiadomość? Na razie AI pisze kod tak charakterystyczny, że systemy obronne (również oparte na AI) potrafią go wyłapać właśnie przez tę jego „podręcznikowość”. Pytanie brzmi: ile czasu hakerzy będą potrzebowali, by kazać chatbotom pisać kod w sposób „brudny i ludzki”?
#AI #cyberbezpieczeństwo #Google #hakerzy #iMagazineSecurity #Mandiant #technologia #zeroDayGoogle Finanse z AI trafiają do Polski. Nowa wersja ma pomóc inwestorom w analizie rynku
-
Lanscope Endpoint Manager Zero-Day Exploited in the Wild https://www.securityweek.com/lanscope-endpoint-manager-zero-day-exploited-in-the-wild/ #Vulnerabilities #vulnerability #exploited #Lanscope #ZeroDay #Motex
-
🔒 Microsoft confirms Medusa ransomware is actively exploiting a CVSS 10.0 deserialization flaw in Fortra’s #GoAnywhere MFT. If your GoAnywhere instance is internet-exposed, patch immediately.
Read: https://hackread.com/medusa-ransomware-goanywhere-mft-flaw-microsoft/
-
Fortra GoAnywhere MFT Zero-Day Exploited in Ransomware Attacks https://www.securityweek.com/fortra-goanywhere-mft-zero-day-exploited-in-ransomware-attacks/ #Vulnerabilities #vulnerability #GoAnywhere #Ransomware #exploited #ZeroDay #Fortra
-
Fortra GoAnywhere MFT Zero-Day Exploited in Ransomware Attacks https://www.securityweek.com/fortra-goanywhere-mft-zero-day-exploited-in-ransomware-attacks/ #Vulnerabilities #vulnerability #GoAnywhere #Ransomware #exploited #ZeroDay #Fortra
-
Sztuczna inteligencja w rękach hakerów. Nowe narzędzie łamie zabezpieczenia w 10 minut
Eksperci ds. cyberbezpieczeństwa od dawna ostrzegali przed dniem, w którym zaawansowana sztuczna inteligencja zostanie skutecznie wykorzystana jako broń przez hakerów. Wygląda na to, że ten dzień już nadszedł.
Według firmy Check Point taki scenariusz właśnie przestał być przyszłością, a stał się teraźniejszością. Narzędzie o nazwie Hexstrike-AI, pierwotnie stworzone do testowania zabezpieczeń, zostało przejęte i zmodyfikowane przez cyberprzestępców, pozwalając im na wykorzystywanie luk typu zero-day w czasie krótszym niż 10 minut. Przy czym nie chodzi o znane cyberprzestępcom luki zero-day, lecz o fakt, że AI jest w stanie w bardzo krótkim czasie takie właśnie luki znaleźć i wykorzystać.
Gigantyczna platforma AI pod ochroną Cisco. ClamAV przeskanuje miliony modeli
Hexstrike-AI zostało zaprojektowane jako „ofensywna platforma bezpieczeństwa oparta na AI”, mająca pomagać firmom w znajdowaniu i naprawianiu własnych słabości. Działa jak dyrygent, zarządzając ponad 150 wyspecjalizowanymi agentami AI i narzędziami bezpieczeństwa w celu symulowania zaawansowanych ataków. Problem polega na tym, że to, co czyni narzędzie skutecznym dla obrońców, czyni je również niezwykle potężnym w rękach atakujących. Niemal natychmiast po jego publicznym zaprezentowaniu, na forach w dark webie rozpoczęły się dyskusje na temat jego zbrodniczego wykorzystania.
Pojawienie się narzędzia zbiegło się w czasie z ogłoszeniem przez firmę Citrix trzech poważnych luk typu „zero-day” w jej popularnych produktach NetScaler. Podatność „zero-day” to błąd, na który nie istnieje jeszcze oficjalna łatka, co pozostawia systemy całkowicie bezbronnymi. Standardowo, wykorzystanie tak złożonych luk wymagałoby dni, a nawet tygodni pracy zespołu wysoko wykwalifikowanych hakerów. Przy czym istotna uwaga: żadna firma publikująca informacje o lukach zero-day we własnych produktach nie informuje o tym fakcie zanim dana luka nie zostanie załatana, to chyba oczywiste, ale podaję tak na wszelki wypadek.
Sztuczna inteligencja to miecz obosieczny dla naszej cyfrowej tożsamości. Nowy raport Cisco
W każdym razie z pomocą Hexstrike-AI, ten proces wyszukiwania podatności w oprogramowaniu został skrócony do niecałych 10 minut. Atakujący musi jedynie wydać prostą komendę, a system samodzielnie dobiera odpowiednie narzędzia i wykonuje wszystkie niezbędne kroki. To swego rodzaju „demokratyzacja hakowania”, która automatyzuje i upraszcza procesy dotychczas dostępne tylko dla ekspertów. „Obserwowanie, jak wszystko działa bez mojego udziału, to po prostu poezja. Nie jestem już programistą-robotnikiem, ale operatorem” – chwalił się jeden z cyberprzestępców na forum.
Według Check Point, szybkość i skala ataków przeprowadzanych z użyciem AI dramatycznie skracają czas, jaki firmy mają na reakcję i zabezpieczenie swoich systemów. Eksperci z firmy wzywają organizacje do podjęcia natychmiastowych działań, w tym do bezzwłocznego instalowania wydanych już łatek na produkty Citrix oraz do inwestycji w systemy obronne oparte na AI, które jako jedyne mogą reagować na zagrożenia z maszynową prędkością. Monitorowanie dark webu w poszukiwaniu informacji o nowych zagrożeniach również staje się, zdaniem firmy, absolutną koniecznością.
#AI #bezpieczeństwoCyfrowe #CheckPoint #CitrixNetScaler #cyberatak #cybersecurity #darkWeb #hakerzy #HexstrikeAI #news #podatność #sztucznaInteligencja #zeroDay
-
Pilna aktualizacja dla iPhone’ów. Apple i polskie wojsko ostrzegają przed groźną luką w iOS
Apple udostępniła krytyczną aktualizację bezpieczeństwa do wersji iOS 18.6.2. Zarówno producent, jak i polskie Wojska Obrony Cyberprzestrzeni, wzywają do jej natychmiastowej instalacji. Powodem jest groźna luka w oprogramowaniu, która jest już aktywnie wykorzystywana przez hakerów w cyberatakach.
Komunikat o zagrożeniu został opublikowany m.in. na oficjalnych kanałach Wojsk Obrony Cyberprzestrzeni. Eksperci wojskowi podkreślają, że wykryta luka jest już wykorzystywana w atakach, a kilkuminutowa aktualizacja „może ochronić dane i prywatność” użytkowników. To rzadka sytuacja, w której krajowa jednostka ds. cyberbezpieczeństwa wydaje tak bezpośrednie zalecenie dotyczące oprogramowania konsumenckiego.
🚨 PILNE⁰W systemie iOS wykryto poważną lukę bezpieczeństwa, która jest już aktywnie wykorzystywana w cyberatakach.
📲 Apple udostępniło aktualizację iOS 18.6.2 – warto zainstalować ją jak najszybciej. To tylko kilka minut, które mogą ochronić dane i prywatność.#CyberSecurity… pic.twitter.com/NiEck7GfNX
— Karol Molenda (@MolendaKarol) August 23, 2025
Samo Apple potwierdziło powagę sytuacji, informując w nocie bezpieczeństwa, że jest „świadome raportów mówiących o wykorzystaniu tej luki w atakach na konkretne osoby”. Taka deklaracja oznacza, że mamy do czynienia z podatnością typu zero-day – czyli taką, o której cyberprzestępcy dowiedzieli się przed producentem i zdążyli ją wykorzystać, zanim powstała oficjalna poprawka. Z ujawnionych informacji wynika, że luka (CVE-2025-43300) tkwi w systemowym frameworku ImageIO i może zostać aktywowana przez przetworzenie złośliwie spreparowanego pliku graficznego.
Ani Apple, ani wojsko nie precyzują, kto jest celem ataków. Jednak ze względu na charakter luki, zalecenie aktualizacji dotyczy wszystkich użytkowników. Narażone są modele iPhone XS i nowsze.
Aby zainstalować aktualizację, należy wejść w Ustawienia > Ogólne > Uaktualnienia i wybrać opcję instalacji iOS 18.6.2. Jeśli włączone są aktualizacje automatyczne, urządzenie powinno samo pobrać i zainstalować łatkę. Ze względu na powagę zagrożenia, nie warto jednak z tym zwlekać.
#aktualizacja #Apple #Bezpieczeństwo #cyberbezpieczeństwo #hakerzy #iOS #iPhone #lukaBezpieczeństwa #news #WojskaObronyCyberprzestrzeni #zeroDay
-
Zero-Day Exploit in WinRAR File – Source: www.schneier.com https://ciso2ciso.com/zero-day-exploit-in-winrar-file-source-www-schneier-com/ #rssfeedpostgeneratorecho #SchneierOnSecurity #SchneieronSecurity #CyberSecurityNews #Uncategorized #exploits #Malware #zeroday #Russia
-
Alright team, it's been a pretty eventful 24 hours in the cyber world! We've got critical zero-days under active exploitation, several significant breaches, new spyware, and a big debate on national cyber strategy. Let's dive in:
Microsoft SharePoint Zero-Day Under Active Exploitation ⚠️
- A critical remote code execution (RCE) zero-day, CVE-2025-53770 (CVSS 9.8), is being actively exploited in on-premises Microsoft SharePoint servers globally. This flaw is a bypass of a patch for a previous vulnerability (CVE-2025-49706) released in July's Patch Tuesday.
- Attackers, suspected to be nation-state actors, are using an exploit dubbed "ToolShell" to gain unauthenticated access, exfiltrate sensitive data, deploy backdoors, and steal cryptographic machine keys, allowing persistent access even after patching.
- Microsoft has released emergency patches for SharePoint Server 2019 and Subscription Edition, but SharePoint Server 2016 remains unpatched. Organisations with public-facing on-prem SharePoint should assume compromise, investigate for malicious files (e.g., spinstall0.aspx), rotate machine keys, and consider disconnecting servers if immediate patching isn't possible.
🗞️ The Record | https://therecord.media/microsoft-sharepoint-zero-day-vulnerability-exploited-globally
🤖 Bleeping Computer | https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-patches-for-sharepoint-rce-flaws-exploited-in-attacks/
🕵🏼 The Register | https://go.theregister.com/feed/www.theregister.com/2025/07/21/infosec_in_brief/
🤫 CyberScoop | https://cyberscoop.com/microsoft-sharepoint-zero-day-attack-spree/
🕵🏼 The Register | https://go.theregister.com/feed/www.theregister.com/2025/07/21/massive_security_snafu_microsoft/CrushFTP Zero-Day Under Active Exploitation 🛡️
- CrushFTP is warning customers about CVE-2025-54309, a critical zero-day actively exploited since at least July 18th, allowing attackers to gain administrative access to the web interface due to mishandled AS2 validation.
- The vulnerability affects all CrushFTP versions below 10.8.5 and 11.3.4_23. Over 1,000 unpatched instances are exposed online, with some attackers manipulating exploited versions to appear up-to-date.
- Admins should immediately update to the latest versions, review upload/download logs for unusual activity, enable automatic updates, and consider IP whitelisting or using a DMZ instance to mitigate exploitation.
🤖 Bleeping Computer | https://www.bleepingcomputer.com/news/security/over-1-000-crushftp-servers-exposed-to-ongoing-hijack-attacks/
🗞️ The Record | https://therecord.media/file-transfer-crushftp-zero-dayPoland Investigates Air Traffic Control Disruption 🚨
- Poland's internal security agency is investigating a temporary outage in the country's air traffic control system that caused widespread flight delays on Saturday, with potential sabotage being scrutinised.
- The outage was attributed to an unspecified technical malfunction, not a cyberattack, but national security services are looking for signs of sabotage given Poland's heightened alert over suspected Russian-linked acts.
- This incident follows previous accusations by Poland against Moscow for "air terror" operations and involvement in a 2023 shopping centre fire, highlighting ongoing hybrid threats in the region.
🗞️ The Record | https://therecord.media/poland-investigates-potential-sabotage-air-traffic-controlAlaska Airlines Grounds Fleet Due to IT Issue ✈️
- Alaska Airlines temporarily grounded its fleet due to an unspecified IT issue, causing significant operational disruption.
- While the nature of the incident is unconfirmed, the Scattered Spider ransomware gang, known for targeting airlines, is an obvious suspect, especially given recent incidents affecting Hawaiian Airlines (owned by Alaska), Qantas, and Air Serbia.
- The airline has apologised for the inconvenience and is working to resolve the issues, advising customers to check flight status before heading to the airport.
🕵🏼 The Register | https://go.theregister.com/feed/www.theregister.com/2025/07/21/alaska_airlines_it_incident_grounding/Indian Crypto Exchange CoinDCX Suffers $44M Theft 💰
- Indian cryptocurrency exchange CoinDCX confirmed a theft of over $44 million worth of USDC and USDT from one of its internal operational accounts over the weekend.
- User funds were not impacted as operational accounts are segregated from customer wallets, and CoinDCX is absorbing the losses from its own treasury reserves.
- The company is investigating, patching vulnerabilities, and tracing the stolen funds, offering a bug bounty program and up to 25% of recovered funds for assistance.
🗞️ The Record | https://therecord.media/indian-crypto-dcx-millions-stolenDell Product Demo Platform Breached 💻
- Dell confirmed a breach of its "Solution Center" product demonstration platform by a threat actor, but stated that no sensitive customer or partner information was involved.
- The platform is intentionally separated from Dell's main networks and customer systems, and the data contained is primarily synthetic or publicly available test data.
- The WorldLeaks ransomware gang (a revamp of Hunters International) has claimed responsibility for the incident, which Dell says had limited impact.
🗞️ The Record | https://therecord.media/hackers-hit-dell-product-demo-platform-limited-impactDior Notifies US Customers of Data Breach 🛍️
- The luxury fashion house Dior is sending data breach notifications to US customers following a cybersecurity incident on January 26, 2025, discovered on May 7, 2025.
- Exposed information includes full names, contact details, physical addresses, dates of birth, and in some cases, passport/government ID numbers and Social Security Numbers. No payment details were compromised.
- This incident is believed to be linked to the ShinyHunters extortion group, which previously breached a third-party vendor affecting other LVMH brands like Louis Vuitton.
🤖 Bleeping Computer | https://www.bleepingcomputer.com/news/security/dior-begins-sending-data-breach-notifications-to-us-customers/Ring Denies Breach Amid Suspicious Login Reports 🏠
- Ring is attributing a surge in suspicious login reports from May 28th to a "backend update bug" that incorrectly displays prior login dates and devices.
- However, many customers are disputing Ring's explanation, reporting unknown devices, strange IP addresses, and countries they've never visited, along with unreceived MFA prompts and live view activity when no one accessed the app.
- Users are advised to review authorized devices in the Control Center, remove unrecognized entries, change passwords, and enable two-factor authentication.
🤖 Bleeping Computer | https://www.bleepingcomputer.com/news/security/ring-denies-breach-after-users-report-suspicious-logins/Arizona Election Website Defaced, CISA Criticised 🗳️
- Arizona election officials reported a hack on a statewide online portal for political candidates, resulting in the defacement of candidate photos with images of the late Iranian Ayatollah Ruhollah Khomeini.
- The attack, which occurred after US bombings of Iranian nuclear sites, involved uploading an image file containing a Base64-encoded PowerShell script to take over the server. Officials believe it was pro-Iranian interests.
- Arizona's Secretary of State criticised CISA, claiming the agency has been "weakened and politicized" under the current administration, leading to a loss of confidence in federal election security support.
🤫 CyberScoop | https://cyberscoop.com/arizona-secretary-of-state-website-hack-candidate-portal-criticizes-cisa/New Iranian Android Spyware Discovered 📱
- Lookout security researchers have discovered four new samples of DCHSpy Android spyware, linked to the Iranian Ministry of Intelligence and Security (MOIS), surfacing shortly after the Iran-Israel conflict began.
- Disguised as VPN apps (Earth VPN, Comodo VPN), the malware collects WhatsApp data, records audio/video, and exfiltrates sensitive files, indicating continued development and usage by the MuddyWater espionage group.
- The distribution via Telegram channels, sometimes using "Starlink" lures, suggests targeting Iranian dissidents, activists, and journalists, highlighting the MOIS's efforts to surveil citizens.
🕵🏼 The Register | https://go.theregister.com/feed/www.theregister.com/2025/07/21/muddywaters_android_iran/ExpressVPN Fixes RDP IP Leak Bug 🔒
- ExpressVPN has patched a flaw in its Windows client (versions 12.97 to 12.101.0.2-beta) that caused Remote Desktop Protocol (RDP) traffic to bypass the VPN tunnel, exposing users' real IP addresses.
- The issue stemmed from debug code mistakenly included in production builds. While encryption wasn't compromised, RDP traffic was visible to observers like ISPs.
- Users are advised to upgrade to version 12.101.0.45 immediately. ExpressVPN states the risk was low for typical consumers as RDP is primarily used by IT admins and enterprises.
🤖 Bleeping Computer | https://www.bleepingcomputer.com/news/security/expressvpn-bug-leaked-user-ips-in-remote-desktop-sessions/US Cyber Posture Shift: From Defense to Offense 🇺🇸
- The US is reportedly shifting its cyber posture towards more robust offensive operations, backed by a proposed $1 billion cyber initiative under the 2026 National Defense Authorization Act (NDAA).
- This pivot is driven by a changing threat landscape where adversaries like China's Volt Typhoon and Russia's campaigns are actively preparing for conflict and disruption, not just espionage.
- The argument is that a defensive-only approach has emboldened adversaries, and a more muscular cyber posture, integrating offensive capabilities with military and intelligence operations, is necessary for deterrence and to impose costs.
🤫 CyberScoop | https://cyberscoop.com/us-offensive-cyber-operations-2025-defense-shift-op-ed/#CyberSecurity #ThreatIntelligence #ZeroDay #Vulnerability #RCE #SharePoint #CrushFTP #CyberAttack #DataBreach #Ransomware #Spyware #NationState #InfoSec #IncidentResponse #CyberWarfare
-
Exploited CrushFTP Zero-Day Provides Admin Access to Servers https://www.securityweek.com/exploited-crushftp-zero-day-provides-admin-access-to-servers/ #Vulnerabilities #exploited #CrushFTP #ZeroDay