๐จ ACTIVE EXPLOITATION
- Hackers run khunt post-exploitation toolkit from Oracle database
Hackers used an Oracle database to run the khunt post-exploitation toolkit.
- Huntress observed the attack against a corporate network using an Oracle database server.
- A public-facing Java application running Apache Tomcat was vulnerable to SQL injection through its autocomplete search endpoint.
- Attackers stored khunt as Oracle Java objects and executed it through SQL commands.
- khunt components enabled command execution, credential theft, file access, and archive extraction.
- The attackers ran commands with Windows SYSTEM privileges and connected from 178.162.151[.]229. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ฅ BREACHES & INCIDENTS
- Canadian hacker pleads guilty after compromising 165 organizations
Connor Moucka pleaded guilty to hacking at least 165 organizations and extorting victims.
- Moucka and co-conspirators targeted at least 165 customers of a U.S.-based software-as-a-service company.
- They stole billions of customer records and terabytes of data, affecting at least 100 million individuals.
- The stolen data included call and text histories, financial information, payroll records, and identity documents.
- Attackers used stolen login credentials to access cloud-hosted customer data and threatened to publish it.
- They advertised stolen data on BreachForums, Exploit.in, XSS.is, and Telegram, collecting more than $2.5 million in ransom payments. ๐ Coverage: justice.gov ยท ๐ via @metacurity@infosec.exchange
๐ต๏ธ RESEARCH & DEEP DIVES
-
Researchers Used a $50,000 Exploit Chain to Hijack Samsung Phones via Bixby Researchers demonstrated a chained attack that gained system-level control of Samsung phones through Bixby.
- Samsung Galaxy S25, S24, and Flip 7 smartphones were successfully compromised; older devices may also be affected.
- Samsung Members and Samsung Account vulnerabilities enabled attacks against phones with those apps installed.
- Malicious ads or messaging links led victims to attacker-controlled websites.
CVE-2025-21079,CVE-2025-58486, andCVE-2025-58487chained redirects, XSS, and Bixby access.- Abusing Bixby Capsules enabled sensitive-data theft, remote code execution, and system-level device control. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
Cyber Operations Become a Fourth Domain of Global Conflict Nation states increasingly use cyber operations to support geopolitical and military objectives.
- Governments, militaries, and commercial enterprises face nation-state cyber operations.
- China, Russia, Iran, and North Korea are identified as major state actors.
- Operations target military capabilities, intelligence, and intellectual property through espionage.
- Cyber activity can precede kinetic conflict or cause physical damage in cyber-kinetic attacks.
- Nation-state campaigns are typically low and slow, emphasizing stealth and prolonged network dwell time. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
Malware Can Hijack Accounts Protected by Google-Synced Passkeys Palo Alto Networks researchers demonstrated malware attacks that hijack Google-synced passkey accounts.
- The attacks target Google-synced passkeys used with Chrome on Windows machines.
- Pass-ta-key malware accesses Chrome's local synchronization database and recovers a device identity key.
- Windows cryptographic APIs let the malware sign Google authentication challenges without biometric verification, device unlock, or elevated privileges.
- Silver Pass-ta-key registers an attacker-controlled verification key during Chrome re-registration.
- Golden Pass-ta-key extracts a master secret from Chrome memory to decrypt synchronized passkey private keys. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
Brown Health Medical Group-MA Breach Affects 311,760 People A data breach at Brown Health Medical Group-MA affected 311,760 people.
- Lifespan Physician Group of Massachusetts, doing business as Brown Health Medical Group-MA, was affected.
- The breach exposed personal, medical, financial, personnel, and human resources information.
- Attackers accessed a historic file server at the organization's Hawthorn location in December 2025.
- The electronic health record system was not affected; no threat actor or ransomware group has claimed responsibility. ๐ Coverage: securityweek.com ยท ๐ via Security