๐จ ACTIVE EXPLOITATION
-
ChainDrop worm poisoned 444 npm packages to steal developer credentials ChainDrop compromised hundreds of npm packages with a self-propagating credential stealer.
- Developers, CI/CD runners, and cloud environments using affected npm packages were exposed.
- The worm poisoned 444 packages across 2,212 versions, including keyv 6.0.0, flat-cache 6.1.24, and file-entry-cache 11.1.6.
- A preinstall hook runs setup.mjs, which downloads Bun v1.3.13 and launches the obfuscated Math_Symbol.js or math_init.js payload.
- The payload harvests npm, GitHub, cloud, Kubernetes, Vault, and AI-tool credentials before republishing packages with stolen tokens. ๐ Source: elastic.co ยท ๐ Coverage: stepsecurity.io ยท ๐ via Cyber Security News
-
Greatness AiTM Campaign Hijacks Microsoft 365 Accounts for Payroll Intelligence Greatness phishing campaigns are hijacking Microsoft 365 accounts to target payroll and finance data.
- Microsoft 365 users across the US, Canada, UK, Australia, and South Africa are targeted.
- The Greatness PhaaS steals credentials, MFA-approved tokens, OAuth device tokens, and Microsoft 365 data.
- Spoofed RingCentral voicemail and performance-review emails bypassed safe-sender filters despite failing SPF, DKIM, and DMARC.
- AiTM proxies relay sign-ins while device-code flows capture tokens for later replay from VPN and VPS infrastructure.
- Observed infrastructure includes 38.248.95[.]214, 158.173.166[.]3, and finreportviewersoftware[.]sbs; access persisted for more than two weeks. ๐ Source: zerobec.com ยท ๐ Coverage: bleepingcomputer.com ยท ๐ via The Hacker News
-
Keyv-linked npm worm spreads credential stealer across hundreds of packages A credential-stealing worm spread through hundreds of malicious npm package versions.
- Developers and CI environments using Keyv, Cacheable, Ecto, and related npm packages were affected.
- SafeDep verified 353 poisoned versions across 79 package names, including keyv@6.0.0 and cache-manager@7.2.10.
- A preinstall script launched a Bun-based loader that harvested GitHub, npm, cloud, CI, Kubernetes, and private-key credentials.
- The worm propagated using stolen npm or GitHub credentials and added Claude Code and VS Code execution hooks.
- Known indicators include Math_Symbol.js, math_init.js, Bun/1.3.13, and npm-cache[.]com. ๐ Source: github.com ยท ๐ Coverage: securitylabs.datadoghq.com ยท ๐ via @metacurity@infosec.exchange
๐ RESEARCH & DEEP DIVES
-
HTTP Terminator Finds New Desync Techniques and Apache Traffic Server Zero-Day
CVE-2026-63078PortSwigger reported new HTTP desync techniques and an Apache Traffic Server zero-day.- Findings affected websites across banks, government infrastructure, security products, and an airport.
- Apache Traffic Server had a desynchronization zero-day tracked as CVE-2026-63078.
- HTTP Terminator generated 30,000 candidate vectors and tested 30,000 authorized websites, finding about 700 vulnerable targets.
- Multipart/byteranges triggers and a dangling-byte technique enabled response queue poisoning.
- Response queue poisoning could expose other users' session cookies or API keys; a malformed request cascade revealed the Apache flaw. ๐ Source: portswigger.net ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
AI Coding-Agent Workflows Exposed CI Secrets to Zero-Privilege GitHub Issues
CVE-2026-54316Novee Security found that zero-privilege GitHub issues could compromise Claude Code, Gemini CLI, and Codex workflows.- The affected products are Anthropic Claude Code Action, Google Gemini CLI and GitHub Action, and OpenAI Codex workflows.
- Attackers could execute code on CI runners, steal GITHUB_TOKEN and API credentials, and compromise software supply chains.
- A malicious GitHub issue or pull request delivered prompt injection to agents with shell, file, web, or repository access.
- OpenAI Codex workflows could be persistently hijacked when one agent run wrote a trusted AGENTS.md file for a later run.
- Affected Gemini versions were CLI releases before 0.39.1, preview releases before 0.40.0-preview.3, and run-gemini-cli action versions before 0.1.22; Anthropic's disclosure included CVE-2026-54316. ๐ Source: novee.security ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Windows Hello for Business Keys Can Enable Persistent Entra ID Access Researchers showed malware can misuse Windows Hello for Business keys to persist in Entra ID.
- Microsoft Entra ID tenants using Windows Hello for Business are affected.
- Malware in a signed-in Windows session can invoke the user's WHfB key without the PIN, biometric prompt, or administrator rights.
- The technique uses WebAuthn to treat the WHfB key as a FIDO2 passkey and generate signed authentication assertions.
- Attackers can obtain Primary Refresh Tokens, register attacker-controlled devices, and add authentication methods where tenant policies permit. ๐ Source: dirkjanm.io ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
UNC6671 Rebrands Across Multiple Vishing Extortion Brands UNC6671 is targeting financial and enterprise organizations with vishing-led cloud extortion.
- Targets include financial services, private equity, hedge funds, law firms, and other enterprises.
- The operation spans the BlackFile, Redact, Pink, Helix, and Falcon extortion brands.
- Attackers call employees' personal mobiles while impersonating IT help desks handling urgent passkey or MFA updates.
- Lookalike portals use adversary-in-the-middle phishing to steal credentials, MFA tokens, and session cookies.
- Stolen Microsoft 365 and Okta access enables automated SaaS data theft and mailbox notification deletion; observed domains include passkeyhelpdesk[.]com and passkeydeploy[.]com. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
NatJack Attacks Manipulate NAT Tables to Hijack TCP and Spoof DNS
CVE-2026-56181CVE-2026-63913Researchers disclosed NatJack attacks against shared NAT infrastructure.- The techniques affect NAT implementations across Windows, Linux, macOS, and 32 tested products and configurations.
- Windows Hyper-V NAT is affected by CVE-2026-56181, while Linux Netfilter conntrack is affected by CVE-2026-63913.
- Windows releases affected include Windows 11 24H2 before 26100.8875, 25H2 before 26200.8875, 26H1 before 28000.2525, and Server 2025 before 26100.33158.
- An attacker with a system behind the same NAT uses spoofed packets to corrupt connection-tracking entries and redirect active TCP sessions.
- NatJack also poisons DNS responses, identifies mapped ports, and exhausts NAT tables with spoofed flows. ๐ Source: natjack.io ยท ๐ Coverage: networkworld.com ยท ๐ via The Hacker News
๐ ADVISORIES
- Bendix EC80 Brake Controller Recall Also Fixed Hidden Security Flaws
A Bendix EC80 brake controller recall also addressed remote code execution and DoS flaws.
- Truck operators using Bendix EC80 brake controllers were affected.
- The controller had remote code execution and denial-of-service vulnerabilities.
- The safety recall included a previously undisclosed security fix.
- NMFTA researchers identified the security issues. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
๐ CVEs & KEV
- Other: 16 CVEs (worst 9.5)