Click any tag below to further narrow down your results
Links
Attackers hijack WhatsApp accounts to send obfuscated VBScript files named as business or financial documents. When opened, the script disables UAC, downloads ManageEngine Endpoint Central, and connects the PC to attacker-controlled servers for remote administration. The campaign hits users in over a dozen countries, though how WhatsApp accounts are first compromised remains unclear.
- Attackers are hijacking WhatsApp accounts to send malicious VBScript files disguised as invoices or financial reports, hitting users across 11+ countries.
- Opening the file disables UAC, then silently installs the legitimate ManageEngine Endpoint Central tool to give attackers full remote control of the PC.
- Code artifacts point to Chinese-language origins and overlap with ValleyRAT/Gh0st RAT infrastructure, though no group has been formally attributed.
- It's still unknown how the attackers are initially compromising victims' WhatsApp accounts.
This roundup covers a WhatsApp phishing campaign that uses fake business docs to drop remote-access malware on Windows PCs, Cisco’s move to secure AI agents by integrating WideField into Splunk, and why buying SaaS still beats building even with cheaper AI tools. It also highlights identity governance gaps for AI agents, Zoom Rooms’ expanded status dashboard, Flic Mic’s new wireless push-to-talk device, OpenAI’s Daybreak patch automation, and a terminal Markdown viewer called MdFried.
- WhatsApp phishing campaign tricks users into opening fake business/finance docs that install ManageEngine Endpoint Central, giving attackers full admin access to Windows PCs.
- Cisco is acquiring WideField Security to bring identity governance for both human and AI-agent identities into Splunk, aiming to track risky agent actions and every credential type.
- SaaS still beats building in-house for many tools despite cheaper AI-assisted development, because established products carry lower maintenance overhead than custom builds.
- Most current identity tools only track registered agents/managed platforms, missing the app-level visibility and real-time authorization needed for true AI agent governance.
This digest covers a range of InfoSec news, from a Salesforce data theft via a compromised Klue integration and a mass phishing campaign impersonating Boots, to the discovery of GlassWASM WebAssembly malware hidden in trojanized Open VSX extensions. It also highlights red-teaming honey pot detection, recent ASUS driver CVEs, a Dropping Elephant loader chain, and Homebrew 6.0’s new security features.
- Compromised Klue OAuth tokens let the Icarus extortion group siphon Salesforce data via ~1,000 API calls in 15-minute bursts over a full day
- Romanian phishers spoofed a Boots "free sample" campaign, hitting ~9 million customers via a hacked Bolivian government checkout page and a compromised UK mail server
- GlassWASM malware hides in trojanized Open VSX extensions (ExarGD.vsblack, noellee-doc/flint-debug), using a Solana wallet to fetch encrypted C2 addresses for second-stage payloads
- Homebrew 6.0 adds default Bubblewrap sandboxing on Linux, a tap-trust opt-in system, and an OSV-based `brew vulns` vulnerability scanner