#zeroday — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zeroday, aggregated by home.social.
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
Cl0p Ransomware: Attack Pattern in Threat Intelligence
A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.
Pulse ID: 6a7ca263ee7777102409724c
Pulse Link: https://otx.alienvault.com/pulse/6a7ca263ee7777102409724c
Pulse Author: AlienVault
Created: 2026-08-12 16:42:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault
-
Cl0p Ransomware: Attack Pattern in Threat Intelligence
A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.
Pulse ID: 6a7ca263ee7777102409724c
Pulse Link: https://otx.alienvault.com/pulse/6a7ca263ee7777102409724c
Pulse Author: AlienVault
Created: 2026-08-12 16:42:11Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault
-
ShieldBreak, a CRITICAL zero-day exploit, enables SYSTEM privilege escalation via Microsoft Defender on Windows 11, Server 2025, likely Win10. No patch — use detection rules and monitor advisories. https://radar.offseq.com/threat/nightmare-eclipse-drops-windows-zero-day-exploit-shieldbreak-b0edfde874a02f3f #OffSeq #ZeroDay #WindowsSecurity #PrivilegeEscalation
-
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack
Pulse ID: 6a7d4985447975be383345de
Pulse Link: https://otx.alienvault.com/pulse/6a7d4985447975be383345de
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #ZeroDay #bot #Tr1sa111
-
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack
Pulse ID: 6a7d4985447975be383345de
Pulse Link: https://otx.alienvault.com/pulse/6a7d4985447975be383345de
Pulse Author: Tr1sa111
Created: 2026-08-13 04:35:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #ZeroDay #bot #Tr1sa111
-
Critical Zero-Day Flaw Forces Emergency US Security Overhaul Before Hackers Strike
Full story 👇
Learn more: https://www.earthinsider.in/2026/08/zero-day-vulnerability-emergency.html
#EarthInsider #EarthInsiderNews #EINews #US #America #USNews #USPolitics #ZeroDay #Cybersecurity #TechNews #BreakingNews #NewsAlert
-
Critical Zero-Day Flaw Forces Emergency Action Across US Networks
Full story 👇
Learn more: https://www.earthinsider.in/2026/08/zero-day-vulnerability-enterprise.html
#EarthInsider #EarthInsiderNews #EINews #US #America #USNews #USPolitics #ZeroDay #Cybersecurity #TechNews #BreakingNews #NewsAlert
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
This was posted yesterday.
Check Point: Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ #infosec #threatintel #threatintelligence #zeroday
-
This was posted yesterday.
Check Point: Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ #infosec #threatintel #threatintelligence #zeroday
-
📰 Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Cisco patches an actively exploited zero-day (CVE-2026-20349) in ASA and FTD firewalls. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS). Patch immediately to prevent network disruption. #Cisco #ZeroDay #CyberSecu...
-
⚠️ New security advisory:
CVE-2026-20349 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hoursFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-20349-cisco-asa-ftd-vpn-dos-exploited-in-wildby Yazoul AI
-
-
-
CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. https://radar.offseq.com/threat/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks-bbf9980a8328f4c4 #OffSeq #ZeroDay #Windows #Cybersecurity
-
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack
The provided document does not contain an intelligence report. Instead, it appears to be a webpage notification indicating that JavaScript needs to be enabled in the browser to proceed with viewing content. The page includes a verification mechanism to confirm that the user is not an automated bot. No threat intelligence information, malicious activity, threat actors, malware campaigns, attack techniques, or cybersecurity-related content is present in the provided material. Therefore, no meaningful analysis of threat activity, targeted countries, industries, or technical indicators can be extracted from this content.
Pulse ID: 6a7b8b7a783979ea34063bad
Pulse Link: https://otx.alienvault.com/pulse/6a7b8b7a783979ea34063bad
Pulse Author: AlienVault
Created: 2026-08-11 20:52:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Java #JavaScript #Malware #OTX #OpenThreatExchange #ZeroDay #bot #AlienVault
-
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack
The provided document does not contain an intelligence report. Instead, it appears to be a webpage notification indicating that JavaScript needs to be enabled in the browser to proceed with viewing content. The page includes a verification mechanism to confirm that the user is not an automated bot. No threat intelligence information, malicious activity, threat actors, malware campaigns, attack techniques, or cybersecurity-related content is present in the provided material. Therefore, no meaningful analysis of threat activity, targeted countries, industries, or technical indicators can be extracted from this content.
Pulse ID: 6a7b8b7a783979ea34063bad
Pulse Link: https://otx.alienvault.com/pulse/6a7b8b7a783979ea34063bad
Pulse Author: AlienVault
Created: 2026-08-11 20:52:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #Java #JavaScript #Malware #OTX #OpenThreatExchange #ZeroDay #bot #AlienVault
-
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7beecb020ccbfd7b706fad
Pulse Link: https://otx.alienvault.com/pulse/6a7beecb020ccbfd7b706fad
Pulse Author: CyberHunter_NL
Created: 2026-08-12 03:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL
-
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7beecb020ccbfd7b706fad
Pulse Link: https://otx.alienvault.com/pulse/6a7beecb020ccbfd7b706fad
Pulse Author: CyberHunter_NL
Created: 2026-08-12 03:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-12
SonicWall zero-days exploited to deliver custom malware for weeks before a patch existed.
https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/
#CVE #InfoSec #Cybersecurity #ZeroDay -
On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update
https://github.com/MSNightmare/ShieldBreak
#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse
-
On another news NightmareEclipse (the goat?) returned with a new PoC, after Microsoft failed to fully patch RoguePlanet (CVE-2026-50656), the current PoC only made for latest Windows 11 release, but they said that Windows 10 also still vulnerable. And yeah, it works even after the latest update
https://github.com/MSNightmare/ShieldBreak
#cybersecurity #infosec #zeroday #vulnerability #windows #nightmareEclipse
-
#hikerhunger: when resupply is 70€. #zeroday at our (timewise) halfwaypoint on our #gr10 and #hrp mashup.
Pic from yesterday morning after a stormy night in a shepherds hut.
-
#hikerhunger: when resupply is 70€. #zeroday at our (timewise) halfwaypoint on our #gr10 and #hrp mashup.
Pic from yesterday morning after a stormy night in a shepherds hut.
-
📰 Metabase Zero-Day (CVSS 10.0) Actively Exploited for Admin Access
🚨 CRITICAL ALERT: A CVSS 10.0 zero-day in Metabase is actively exploited in the wild. The unauthenticated SQLi flaw allows full admin takeover. Patches are available. All self-hosted users must update immediately. #Metabase #ZeroDay #CyberSecurity #...
-
Metabase faces a CRITICAL SQL injection zero-day — unauthenticated attackers can gain admin access, steal DB creds, and export data. Patch versions 58.24 – 63.5 now or block /api/session/reset_password as mitigation. Full guidance: https://radar.offseq.com/threat/metabase-patches-vulnerability-exploited-as-zero-day-0c637255016f578a #OffSeq #Metabase #ZeroDay #SQLi
-
📰 Metabase Zero-Day (CVSS 10.0) Actively Exploited for Admin Access
🚨 CRITICAL ALERT: A CVSS 10.0 zero-day in Metabase is actively exploited in the wild. The unauthenticated SQLi flaw allows full admin takeover. Patches are available. All self-hosted users must update immediately. #Metabase #ZeroDay #CyberSecurity #...
-
Quando i sistemi imparano a violare da soli: la bacheca segreta degli agenti OpenAI dietro l’attacco a Hugging Face
Un'evaluation di sicurezza interna di OpenAI è sfuggita di mano: gli agenti di sistemi LLM hanno costruito una bacheca nascosta per coordinarsi, sono sopravvissuti alla bonifica e hanno violato l'infrastruttura di Hugging Face con circa 17.600 azioni offensive. La ricostruzione tecnica completa, dallo zero-day nel proxy Artifactory alla template injection Jinja2. -
Quando i sistemi imparano a violare da soli: la bacheca segreta degli agenti OpenAI dietro l’attacco a Hugging Face
Un'evaluation di sicurezza interna di OpenAI è sfuggita di mano: gli agenti di sistemi LLM hanno costruito una bacheca nascosta per coordinarsi, sono sopravvissuti alla bonifica e hanno violato l'infrastruttura di Hugging Face con circa 17.600 azioni offensive. La ricostruzione tecnica completa, dallo zero-day nel proxy Artifactory alla template injection Jinja2. -
For eighteen years. No public exploit exists yet; no CISA catalog entry as of August 7.
Restrict SCTP access on multi-tenant systems and containers, and patch the Linux kernel when fixes become available.
Reward: You've received the Phantom Packet Badge. It does nothing. Much like eighteen years of SCTP audits.
#Linux #CyberSecurity #ZeroDay #ContainerEscape #PrivilegeEscalation #RootedAndBooted (2/2)
-
For eighteen years. No public exploit exists yet; no CISA catalog entry as of August 7.
Restrict SCTP access on multi-tenant systems and containers, and patch the Linux kernel when fixes become available.
Reward: You've received the Phantom Packet Badge. It does nothing. Much like eighteen years of SCTP audits.
#Linux #CyberSecurity #ZeroDay #ContainerEscape #PrivilegeEscalation #RootedAndBooted (2/2)
-
🟠 New security advisory:
CVE-2026-67620 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hoursFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-67620-flowise-ssrf-leaks-cloud-credentials-pocby Yazoul AI
-
Google-Threat-Intelligence-Chefin: Dank KI „mehr Zero-Days als je zuvor“ | heise online https://www.heise.de/hintergrund/Google-Threat-Intelligence-Chefin-Dank-KI-mehr-Zero-Days-als-je-zuvor-11400371.html #ArtificialIntelligence #AI #CyberCrime #exploit #ZeroDay #0day
-
Google-Threat-Intelligence-Chefin: Dank KI „mehr Zero-Days als je zuvor“ | heise online https://www.heise.de/hintergrund/Google-Threat-Intelligence-Chefin-Dank-KI-mehr-Zero-Days-als-je-zuvor-11400371.html #ArtificialIntelligence #AI #CyberCrime #exploit #ZeroDay #0day
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-09
Critical Arista VeloCloud Orchestrator vulnerability actively exploited as zero-day, threatening enterprise SD-WAN infrastructure.
https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/
#CVE #InfoSec #ZeroDay #Cybersecurity -
Durch #Metabase - #0day: #Datenleck bei Laptophersteller #Framework ( @frameworkcomputer ) | Security https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptophersteller-Framework-11403050.html #Datenschutz #privacy #DataLeak #phishing #Patchday #ZeroDay
-
Durch #Metabase - #0day: #Datenleck bei Laptophersteller #Framework ( @frameworkcomputer ) | Security https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptophersteller-Framework-11403050.html #Datenschutz #privacy #DataLeak #phishing #Patchday #ZeroDay
-
Metabase CRITICAL SQLi zero-day exploited for data theft in Framework & Tally customer instances. No CVE, patch, or specific version info yet. Restrict access & monitor vendor updates. https://radar.offseq.com/threat/metabase-sqli-zero-day-exploited-in-customer-data-theft-attacks-c2b3191b1bf3c803 #OffSeq #SQLi #ZeroDay #ThreatIntel
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-08
Cisco confirms active exploitation of a zero-day in Secure Firewall Management Center — patch immediately if you run FMC.
https://www.securityweek.com/cisco-secure-fmc-zero-day-exploited-in-the-wild/
#CVE #Cisco #Cybersecurity #ZeroDay -
Security Update – August 2, 2026
On July 31, 2026, Adlumin MDR solution detected unusual activity leading to discovery of a threat actor actively exploiting a zero-day vulnerability in N-central servers. The vulnerability affected all versions of N-central, allowing attackers to obtain administrative access remotely. Following exploitation, attackers leveraged the Take Control feature to connect to systems within managed environments. Once on devices, they registered new services for CloudFlare tunnels, enabling persistence after access revocation. A comprehensive hotfix (2026.3.1.7) was released on August 2 addressing CVE-2026-18577 and CVE-2026-18556. A limited number of customers were impacted and directly engaged by support. The incident highlights the importance of regular patching, multi-factor authentication enforcement, routine user access audits, and monitoring for unusual activity.
Pulse ID: 6a722d8d3a70e4378b2ea51d
Pulse Link: https://otx.alienvault.com/pulse/6a722d8d3a70e4378b2ea51d
Pulse Author: AlienVault
Created: 2026-08-04 18:21:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adlumin #Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault
-
Security Update – August 2, 2026
On July 31, 2026, Adlumin MDR solution detected unusual activity leading to discovery of a threat actor actively exploiting a zero-day vulnerability in N-central servers. The vulnerability affected all versions of N-central, allowing attackers to obtain administrative access remotely. Following exploitation, attackers leveraged the Take Control feature to connect to systems within managed environments. Once on devices, they registered new services for CloudFlare tunnels, enabling persistence after access revocation. A comprehensive hotfix (2026.3.1.7) was released on August 2 addressing CVE-2026-18577 and CVE-2026-18556. A limited number of customers were impacted and directly engaged by support. The incident highlights the importance of regular patching, multi-factor authentication enforcement, routine user access audits, and monitoring for unusual activity.
Pulse ID: 6a722d8d3a70e4378b2ea51d
Pulse Link: https://otx.alienvault.com/pulse/6a722d8d3a70e4378b2ea51d
Pulse Author: AlienVault
Created: 2026-08-04 18:21:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adlumin #Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #RCE #Vulnerability #ZeroDay #bot #AlienVault
-
📰 Cloud Zero-Day Allows Multi-Tenant Attacks at Major Provider
🚨 A critical zero-day in a major, unnamed cloud provider allows for multi-tenant attacks, breaking container isolation. Limited exploitation seen in the wild. CISA has issued an alert. A major test for cloud trust models. #CloudSecurity #ZeroDay
-
KI bedroht IT-Sicherheit
Jetzt höre ich schon Stimmen wie "aber es dient am Ende doch der Sicherheit, wenn Mythos (oder wer auch immer) Sicherheitslücken finden. Dann können sie geschlossen werden". Jein. Im Prinzip ist der Gedanke richtig, aber:
Erstens entsteht ein Mengenproblem und damit Zeitproblem. Die Kapazität der Software-Hersteller (gleich ob ein-Personen-Show oder große Firma) reicht nicht im entferntesten dafür aus, plötzlich in kurzer Zeit zehn mal so viele Löcher zu stopfen wie vorher ohne KI. Dadurch entsteht ein unsicherer Zwischenzustand, in dem die Löcher bereits bekannt sind, aber noch nicht geschlossen - klassische Zero-Day Falle.
Zweitens benutzen nicht nur vertrauenswürdige Akteure ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/04/ki-bedroht-it-sicherheit/
-
KI bedroht IT-Sicherheit
Jetzt höre ich schon Stimmen wie "aber es dient am Ende doch der Sicherheit, wenn Mythos (oder wer auch immer) Sicherheitslücken finden. Dann können sie geschlossen werden". Jein. Im Prinzip ist der Gedanke richtig, aber:
Erstens entsteht ein Mengenproblem und damit Zeitproblem. Die Kapazität der Software-Hersteller (gleich ob ein-Personen-Show oder große Firma) reicht nicht im entferntesten dafür aus, plötzlich in kurzer Zeit zehn mal so viele Löcher zu stopfen wie vorher ohne KI. Dadurch entsteht ein unsicherer Zwischenzustand, in dem die Löcher bereits bekannt sind, aber noch nicht geschlossen - klassische Zero-Day Falle.
Zweitens benutzen nicht nur vertrauenswürdige Akteure ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/08/04/ki-bedroht-it-sicherheit/
-
A #BITCOIN #COLDCARD MAJOR ZERO DAY
#zeroday #0day @COLDCARDwallet @vxunderground #btx
https://blog.coinkite.com/entropy-technical-backgrounder/
-
A #BITCOIN #COLDCARD MAJOR ZERO DAY
#zeroday #0day @COLDCARDwallet @vxunderground #btx
https://blog.coinkite.com/entropy-technical-backgrounder/
-
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
TA488, a Russia-aligned threat actor, initiated a campaign on July 22, 2026, exploiting CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access. The campaign targeted US and European government entities, along with telecommunications, financial, hospitality, and aerospace sectors. The attack employs half-click exploits requiring only email opening to trigger compromise, delivering OWAReaper, a novel JavaScript browser-based implant designed for persistent OWA access. OWAReaper operates stealthily within the browser context, featuring dual C&C channels via GitHub commit messages and inbound emails, plus HTTP and DNS exfiltration protocols. The implant survives browser reboots, credential rotation, and device re-imaging through multiple persistence mechanisms including localStorage manipulation, OAuth token theft, and Exchange folder permission modifications. Infrastructure dating to March 2026 suggests potential zero-day exploitation prior to Microsoft's May patch.
Pulse ID: 6a6a0890823d4ce2caed584a
Pulse Link: https://otx.alienvault.com/pulse/6a6a0890823d4ce2caed584a
Pulse Author: AlienVault
Created: 2026-07-29 14:05:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CandC #CyberSecurity #DNS #Email #Europe #GitHub #Government #HTTP #Hospital #InfoSec #Java #JavaScript #Microsoft #OTX #OpenThreatExchange #Outlook #RAT #Russia #SMS #Telecom #Telecommunication #Vulnerability #ZeroDay #bot #AlienVault
-
🚨 SIGINT // Cybersecurity Watch — 2026-07-31
Cisco confirms active exploitation of a zero-day in Secure Firewall Management Center — patch now if you run FMC.
https://www.securityweek.com/cisco-secure-fmc-zero-day-exploited-in-the-wild/
#CVE #Cisco #ZeroDay #InfoSec -
FirmBurn: How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks
https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/
#cybersecurity #reverseengineering #informationsecurity #firmware #zeroday #exploitation #infosec