1 link tagged with all of: infosec + phishing + vulnerabilities
Click any tag below to further narrow down your results
Links
This digest covers a range of InfoSec news, from a Salesforce data theft via a compromised Klue integration and a mass phishing campaign impersonating Boots, to the discovery of GlassWASM WebAssembly malware hidden in trojanized Open VSX extensions. It also highlights red-teaming honey pot detection, recent ASUS driver CVEs, a Dropping Elephant loader chain, and Homebrew 6.0โs new security features.
- Compromised Klue OAuth tokens let the Icarus extortion group siphon Salesforce data via ~1,000 API calls in 15-minute bursts over a full day
- Romanian phishers spoofed a Boots "free sample" campaign, hitting ~9 million customers via a hacked Bolivian government checkout page and a compromised UK mail server
- GlassWASM malware hides in trojanized Open VSX extensions (ExarGD.vsblack, noellee-doc/flint-debug), using a Solana wallet to fetch encrypted C2 addresses for second-stage payloads
- Homebrew 6.0 adds default Bubblewrap sandboxing on Linux, a tap-trust opt-in system, and an OSV-based `brew vulns` vulnerability scanner