๐จ ACTIVE EXPLOITATION
-
Flooding Dropper campaign spreads 846 malicious npm packages UPDATE: A campaign has distributed 846 malicious npm packages delivering cross-platform malware.
- The campaign targets developers and CI/CD environments on Windows, Linux, and macOS.
- Packages act as loaders for second-stage malware that can steal data and establish persistence.
- Install or import execution selects a platform payload, downloads it from hardcoded hosts, or reconstructs it through DNS TXT records.
- Payloads launch as detached processes; Windows samples patch security interfaces and use Registry Run keys and scheduled tasks.
- Package names commonly use terms such as "bigops" and "bnpl," with many releases in the 35.x.y version range. ๐ Source: stepsecurity.io ยท ๐ Coverage: sonatype.com ยท ๐ via The Hacker News
-
ClickFix Attacks Deliver macOS Stealer Capable of Draining Crypto Wallets UPDATE: ClickFix attacks are delivering a macOS stealer that drains cryptocurrency wallets.
- macOS users are targeted, including cryptocurrency holders and users with saved credentials.
- The Go-based stealer harvests browser passwords, Apple iCloud Keychain data, cached credentials, and cryptocurrency assets.
- Victims paste a ClickFix command into Terminal, launching a Bash profiler that fetches a CPU-compatible Mach-O payload.
- A DRAIN routine targets Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP wallets, while fake system-error prompts seek macOS credentials.
- Payload staging and command-and-control infrastructure link to Aeza Group, a sanctioned Russian bulletproof hosting provider. ๐ Source: huntress.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
UNC6671 Uses Vishing to Steal SaaS Data From Financial Firms UNC6671 is using vishing to steal SaaS data and extort organizations.
- Financial services, private equity, law firms, and professional-services organizations are targeted.
- Microsoft 365, Okta, and other SaaS data are stolen for extortion.
- Attackers impersonate IT help desks and call employees on personal mobile phones about urgent passkey or MFA changes.
- Spoofed login portals use AiTM phishing to capture credentials, MFA tokens, and session cookies.
- Associated brands include BlackFile, Redact, Pink, Helix, and Falcon; domains include passkeyhelpdesk[.]com and passkeydeploy[.]com. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ฅ BREACHES & INCIDENTS
-
Unlimited Technology Systems breach affects 3.8 million people UPDATE: Unlimited Technology Systems disclosed a breach affecting 3,803,750 people.
- Unlimited Technology Systems provides practice management and revenue-cycle software to healthcare providers.
- Patient data from the company's healthcare-provider clients was impacted, including 3,803,750 individuals.
- Exposed data included names, contact details, Social Security numbers, diagnoses, insurance and claims information, and identity documents.
- An unauthorized actor accessed a commercial data center and exfiltrated files between October 5 and October 10, 2025.
- The incident was discovered on October 19, 2025; no threat actor or ransomware group has claimed responsibility. ๐ Coverage: securityweek.com ยท ๐ via BleepingComputer
-
Ohio man pleads guilty to hacking court database and Connecticut company Michael Rogers pleaded guilty to hacking a Stark County court database and a Connecticut company.
- The case affects Stark County's CJIS court-record system and a Connecticut-based multinational corporation.
- Rogers accessed personal information from court systems serving Canton, Massillon, Alliance and Stark County.
- He used a custom program to query and scrape CJIS data, collecting names and birth dates from nearly 300,000 people.
- He used malware to obtain more than 150,000 employee names, corporate user IDs and passwords from the company.
- Proxy servers rotated his IP address, and he later destroyed a phone, computer and hard drive containing evidence. ๐ Source: storage.courtlistener.com ยท ๐ Coverage: cantonrep.com ยท ๐ via r/cybersecurity
๐ CVEs & KEV
- CVE-2026-64637 โ CVSS 9.9 โ Improper privilege management in the XML-RPC API of Plesk before 18.0.80, all...
- CVE-2026-71847 โ CVSS 8.7 โ Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buf...
- CVE-2025-58375 โ CVSS 8.1 โ Frappe has potential SQL Injection due to missing validationFrappe is a full-...
- CVE-2026-64636 โ CVSS 7.7 โ An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and ...
- CVE-2026-44964 โ CVSS 6.5 โ The OnCallNotificationActivity in the Datadog Android application is declared...
- CVE-2026-47364 โ CVSS 6.5 โ On every successful login, the Datadog Android application calls FirebaseCras...
- CVE-2026-47361 โ CVSS 6.4 โ BubbleChatActivity in the Datadog Android application is declared android:exp...
- CVE-2026-47363 โ CVSS 6.3 โ The launcher activity AppActivity in the Datadog Android application is decla...
๐ต๏ธ RESEARCH & DEEP DIVES
-
tl;dv Firebase flaw exposed 181,874 meeting records and live call IDs UPDATE: A tl;dv Firebase misconfiguration exposed customers' meeting metadata and enabled potential access to live calls.
- tl;dv customers included government agencies, universities, and major companies across 35,003 email domains.
- The exposed Firestore meetings collection contained 181,874 records tied to 84,312 users.
- Records revealed creator emails, Google Meet or Microsoft Teams conference IDs, providers, timestamps, and recording status.
- Authenticated users could obtain a Firebase token through gw.tldv.io/v1/users/firebase/token and query the cross-tenant collection; about 1,000 meetings were reportedly recording at any time.
- More than 1,000 of 27,334 sampled meetings were publicly accessible, exposing 715 invitee email addresses across 228 domains. ๐ Source: bobdahacker.com ยท ๐ Coverage: darkreading.com ยท ๐ via r/netsec
-
Cyberattacks hit municipal water systems across at least seven U.S. states Hackers targeted municipal water and wastewater systems across at least seven U.S. states.
- Municipal water and wastewater utilities in at least seven states were affected.
- More than 30 Minnesota facilities and nine Michigan systems were targeted.
- Attackers remotely accessed internet-facing control devices and changed IP addresses and administrator passwords.
- Utilities lost monitoring and control capabilities, with some operations disrupted or shifted to manual mode. ๐ Source: fbi.gov ยท ๐ Coverage: nbcnews.com ยท ๐ via r/cybersecurity