π΅οΈ RESEARCH & DEEP DIVES
-
Toy Ghouls group deploys new backdoors abusing HiveMQ MQTT and Element messenger
Kaspersky GERT has discovered new Toy Ghouls backdoors that use HiveMQ MQTT broker and Element messenger as C2 servers.- Affects organizations targeted by the Toy Ghouls threat group, as tracked by Kaspersky GERT.
- Two new backdoor variants were discovered, using legitimate services for command-and-control: the HiveMQ MQTT broker and the Matrix-based Element messenger.
- Abusing legitimate messaging and IoT infrastructure helps the attackers blend C2 traffic in with normal service usage.
π Coverage: securelist.com Β· π via Securelist (Kaspersky)
-
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks β Schneier on Security
-
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws β The Hacker News
-
Why judgment is emerging as cybersecurityβs defining skill β CyberScoop
-
Restaurant Menu and Food Ordering before 2.4.12 - Unauthenticated Payment Bypass v... β CVE ThreatInt
-
ePayco Payment Gateway for WooCommerce before 8.4.7 - Unauthenticated Payment Conf... β CVE ThreatInt
-
AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected... β CVE ThreatInt
-
fastify vulnerable to request validation bypass via skipped boolean false sch... β CVE ThreatInt
-
fastify vulnerable to authentication bypass via malformed URLs reaching encap... β CVE ThreatInt
-
Corosync: corosync: integer overflow in check_memb_commit_token_sanity may by... β CVE ThreatInt
-
Memory leak in scan methodMissing release of memory after effective lifetime ... β CVE ThreatInt
-
Cross-Site Request Forgery via Attacker-Controlled REST Detection in MISPA cr... β CVE ThreatInt
-
fastify vulnerable to request body replacement via an async validation result... β CVE ThreatInt
-
Interinfo|DreamMaker - Reflected Cross-site ScriptingDreamMaker developed by ... β CVE ThreatInt
-
Interinfo|DreamMaker - SQL InjectionDreamMaker developed by Interinfo has a S... β CVE ThreatInt
-
MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Reque... β CVE ThreatInt
-
WordPress WoodMart theme before 8.3.8 - Cross Site Scripting (XSS) vulnerabilityIm... β CVE ThreatInt
-
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form... β CVE ThreatInt
-
MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Perm... β CVE ThreatInt
-
Corosync: corosync: heap-based buffer overflow in totempg assembly buffer dur... β CVE ThreatInt
-
PALLET CONTROL products contain an incorrect default permission vulnerability... β CVE ThreatInt
-
MISP Sharing Group Authorization Bypass via Omitted Distribution ParameterAn ... β CVE ThreatInt
-
WordPress WP Rentals theme before 3.16.0 - Insecure Direct Object References (IDOR... β CVE ThreatInt
-
Snowflake JDBC Driver auto-configuration account validation permits credentia... β CVE ThreatInt
-
Microsoft Teams to Add QR Code Protection in Teams Messaging β Cyber Security News
-
Supply Chain of Distrust β Microsoft/GitHub Supply-Chain Compromise Targets AI Developers β securityboulevard.com (discovered)
-
Can AI Actually Reduce Application Maintenance Costs, or Does It Just Generate More Code? β securityboulevard.com (discovered)
-
Attacking and Defending SCOM: Management Server Relay and Obtaining Run As Credentials β securityboulevard.com (discovered)
-
Detecting living-off-the-land binaries with Sysmon process events β securityboulevard.com (discovered)