🕵️ THREAT RESEARCH & DEEP DIVES
- Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer — The Hacker News
A new software supply chain attack has compromised multiple Laravel-Lang PHP packages (
laravel-lang/lang,http-statuses,attributes,actions) to distribute a sophisticated credential-stealing framework. The campaign uses newly published malicious tags to push trojanized versions, targeting developers and CI pipelines relying on these popular localization packages. Immediate audit of Laravel-Lang dependencies and package integrity verification is critical to prevent credential exfiltration.
🔓 VULNERABILITIES & CVEs
- ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains — SecurityWeek A stealthy DNS vulnerability dubbed “Underminr” affects approximately 88 million domains, enabling attackers to bypass DNS filtering and cloak command-and-control (C2) traffic behind trusted domain names. This flaw undermines conventional network defenses by hiding malicious connections in legitimate DNS responses, complicating detection and blocking efforts. Network defenders should review DNS filtering policies and monitor for anomalous DNS behaviors indicative of C2 evasion. No CVE assigned yet; tracking ongoing.