🚨 ACTIVE EXPLOITS & INCIDENTS
- Massive Password Spray Campaign Targeting Azure CLI - SecurityWeek Over 81 million login attempts detected targeting Azure CLI accounts, originating from IPv6 ranges linked to hosting provider LSHIY LLC. At least 78 Microsoft accounts compromised. Attackers use automated password spraying to bypass authentication, highlighting urgent need for MFA enforcement and monitoring of Azure CLI access.
🕵️ THREAT RESEARCH & DEEP DIVES
- Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware - The Hacker News Palo Alto Networks Unit 42 reveals attackers registering AI-generated, non-existent domains ("phantom squatting") to host phishing and malware campaigns. This new TTP exploits AI hallucinations to preemptively claim domains that AI tools might suggest, increasing phishing success and evasion of traditional domain monitoring.
- Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery - The Hacker News New research uncovers ClickFix malware distribution using API-driven backends that dynamically serve polymorphic payloads to evade detection. The technique bypasses Windows script scanning by tailoring malware per victim, indicating a sophisticated evolution in social engineering and malware delivery.
📋 VENDOR BULLETINS & ADVISORIES
- Google Patches 382 Chrome Vulnerabilities - SecurityWeek Google released a massive patch batch fixing 382 Chrome vulnerabilities, including 15 critical and 67 high-severity flaws. Exploitation could lead to arbitrary code execution with user privileges. Immediate update to Chrome is strongly advised to mitigate risk.
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution - CIS Advisories Confirms critical Chrome vulnerabilities allowing arbitrary code execution in user context. Attackers exploiting these could install programs, alter data, or escalate privileges depending on user rights. Patch deployment is urgent.
- Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari - SecurityWeek Apple released security updates addressing multiple vulnerabilities in WebKit, kernel, WebRTC, and Web Extensions affecting iPhone, iPad, Mac, and Safari. Some flaws could enable remote code execution or privilege escalation. Immediate patching recommended.
- Adobe Patches Seven Max Severity ColdFusion, Campaign Flaws - BleepingComputer Adobe fixed seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic platforms. Exploits could allow remote code execution and data compromise. Organizations using these platforms should prioritize patching.
💼 INDUSTRY NEWS, M&A & DEALS
- Dawnguard Raises $6.3 Million for Security Architecture Automation Platform - SecurityWeek Dawnguard secured $6.3M funding to advance its platform automating secure cloud architecture design and operations. This investment signals growing demand for automated security posture management in cloud environments.
📰 LESSER-KNOWN / UNDER-REPORTED
- Risky Bulletin: Researcher drops giant cache of zero-days - Risky Business News An anonymous researcher publicly released a large cache of zero-day exploits. The bulletin also notes a sensitive DHS network breach and clarifies Huntress’s denial of insider threat accusations. The zero-day dump may increase exploitation risk; monitoring for related activity is advised.
- Amazon fined $2.25M for withholding evidence from fraud victims - BleepingComputer The FTC fined Amazon $2.25M for blocking identity theft victims’ access to transaction records, impacting fraud investigations. This case underscores the importance of transparent data sharing policies for incident response.
- Why Ask Credentials If There Are Secret Codes? (Metamask Phishing) - SANS ISC New phishing campaign targets Metamask users with sophisticated social engineering, exploiting the wallet’s popularity. Attackers use fake “secret code” prompts to steal credentials and crypto assets. Increased user awareness and phishing detection controls recommended.
- Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls - The Hacker News Anthropic re-enabled global access to Claude Fable 5 AI platform after U.S. Commerce Department lifted export restrictions. While primarily regulatory, this may impact AI-powered security tooling availability and adversarial AI research.