๐ฅ BREACHES & INCIDENTS
- ExfilSquad claims breach of Analog Devices, stealing 570,000 records
ExfilSquad hackers stole about 570,000 records from Analog Devices in a June breach.- Applies to Analog Devices, a major computer chip manufacturer
- Approximately 570,000 customer records including personal information and addresses stolen
- ExfilSquad extortion group took credit for the data theft
- Analog Devices confirmed breach in an SEC 8-K filing, ongoing investigation of data nature
- Leak site does not currently list Analog Devices, suggesting possible ransom payment
๐ Coverage: mastodon.social ยท ๐ Original: sec.gov ยท ๐ via @zackwhittaker@mastodon.social (+1)
๐ต๏ธ RESEARCH & DEEP DIVES
-
VaahCMS 2.0.0-2.3.4 contains malicious JavaScript in security OTP email template
CVE-2026-67595
VaahCMS versions 2.0.0 to 2.3.4 embed malicious JavaScript in OTP email templates.- Applies to VaahCMS versions 2.0.0 through 2.3.4
- Malicious obfuscated JavaScript embedded in Blade template rendering security OTP emails
- Allows remote attackers to execute unauthorized code in browsers rendering affected emails with JavaScript enabled
- Payload opens WebSocket to hardcoded C2 server, installs keylogger on password fields, scrapes WhatsApp Web DOM
- Accepts remote commands to redirect or overwrite the rendered email page
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Anthropic's Mythos AI finds fatal flaw in quantum-resistant HAWK crypto algorithm
Anthropic's Mythos AI discovered a critical weakness in the HAWK post-quantum cryptography algorithm.- Applies to HAWK, a quantum-resistant digital signature scheme under NIST post-quantum cryptography evaluation
- Mythos AI found a new method to exploit automorphism symmetries, halving HAWK's effective key strength
- Attack required about 60 hours and $100,000 compute, combining known mathematical tools in novel ways
- HAWK developer withdrew the algorithm from consideration following the Mythos findings
- Mythos also improved meet-in-the-middle attacks on weakened AES variants, though with limited practical impact
๐ Coverage: arstechnica.com ยท ๐ via @dangoodin@infosec.exchange
๐ CVEs & KEV
- CVE-2026-14643 โ CVSS 5.9 โ undici vulnerable to cross-user information disclosure via whitespace around ...
- CVE-2026-15157 โ CVSS 4.2 โ undici vulnerable to CRLF Injection via blob-like body 'type' propertyundici ...