2 links tagged with all of: infosec + malware + vulnerabilities
Click any tag below to further narrow down your results
Links
This daily digest covers a mass credential harvest via FortiBleed targeting FortiGate firewalls, new backdoors like ModeloRAT and Mistic tied to ransomware brokers, and critical data-exposure flaws in platforms such as Dify AI. It also highlights supply-chain risks in open-source CI/CD workflows, Anthropic’s Mythos model uncovering classified-system weaknesses, and industry moves on AI-driven SecOps and network-layer virtual patching.
- FortiBleed brute-forced 430,000+ FortiGate firewalls since February, harvesting over 110 million credentials across 24 protocols for resale
- Four critical Dify AI flaws (CVE-2026-41947 to -41950) let any console user read other tenants' chats, files, and internal APIs; patched in 1.14.2
- ModeloRAT and diskless Mistic backdoors tied to the Woodgnat access broker use signed pythonw.exe and DLL sideloading to evade detection
- Cordyceps research found 300 CI/CD exploit chains across 30,000 GitHub Actions workflows letting free-tier accounts steal tokens and taint builds at Microsoft, Google, Apache, and Cloudflare
This digest covers a range of InfoSec news, from a Salesforce data theft via a compromised Klue integration and a mass phishing campaign impersonating Boots, to the discovery of GlassWASM WebAssembly malware hidden in trojanized Open VSX extensions. It also highlights red-teaming honey pot detection, recent ASUS driver CVEs, a Dropping Elephant loader chain, and Homebrew 6.0’s new security features.
- Compromised Klue OAuth tokens let the Icarus extortion group siphon Salesforce data via ~1,000 API calls in 15-minute bursts over a full day
- Romanian phishers spoofed a Boots "free sample" campaign, hitting ~9 million customers via a hacked Bolivian government checkout page and a compromised UK mail server
- GlassWASM malware hides in trojanized Open VSX extensions (ExarGD.vsblack, noellee-doc/flint-debug), using a Solana wallet to fetch encrypted C2 addresses for second-stage payloads
- Homebrew 6.0 adds default Bubblewrap sandboxing on Linux, a tap-trust opt-in system, and an OSV-based `brew vulns` vulnerability scanner