GitHub Repositories Compromised in Malware Distribution Campaign
Over 100 GitHub repositories are distributing BoryptGrab Stealer, a malware targeting browser and cryptocurrency wallet data, posing significant risks to users.
Intelligence · Updated daily
AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.
Over 100 GitHub repositories are distributing BoryptGrab Stealer, a malware targeting browser and cryptocurrency wallet data, posing significant risks to users.
The Trump administration's cyber strategy focuses on strengthening deterrence against adversaries, modernizing federal networks, protecting critical infrastructure, and investing in emerging technologies like AI and post-quantum cryptography.
Hackers are increasingly leveraging artificial intelligence (AI) to enhance and accelerate cyberattacks, making them more sophisticated, scalable, and harder to detect. This trend poses a significant risk to organizations as AI tools lower the technical barriers for attackers.
Ransomware operators are using a combination of legitimate Windows tools and the ClickFix technique to deploy DonutLoader malware and CastleRAT backdoors, posing a significant threat to systems.
A critical path traversal vulnerability in the /export endpoint of SiYuan allows arbitrary file reads and secret leakage via double-encoded sequences, risking full system compromise.
The OneUpTime probe executes untrusted user code in an insecure Node.js vm context, allowing attackers to bypass sandboxing and achieve RCE. This PoC highlights the risks of using `vm` for untrusted code execution.
OneUptime's Synthetic Monitor allows untrusted Playwright code execution with access to host browser objects, enabling arbitrary executable spawning. This PoC highlights a direct RCE vector bypassing traditional sandbox escapes.
EC-Council has introduced new AI-related certifications to enhance the U.S. cybersecurity workforce's readiness, reflecting growing demand for AI expertise in security.
CISA has ordered U.S. federal agencies to patch three iOS security flaws exploited by the Coruna exploit kit, which is linked to cyberespionage and crypto-theft attacks.
Cognizant's TriZetto Provider Solutions suffered a data breach exposing health data of over 3.4 million individuals, highlighting critical vulnerabilities in healthcare IT systems.
Pingora versions prior to 0.8.0 are vulnerable to HTTP Request Smuggling due to improper handling of the Upgrade header, allowing attackers to bypass security controls.
Pingora improperly handles HTTP/1.0 request bodies and Transfer-Encoding headers, enabling HTTP request smuggling attacks that bypass security controls. The PoC highlights the importance of proper request parsing in reverse proxies.
The `time-sync` crate was used to exfiltrate `.env` files, highlighting a supply chain attack vector in Rust ecosystem. Defenders should focus on monitoring and securing package repositories.
Delta Electronics' CNCSoft-G2 software has a critical vulnerability that enables remote code execution, posing significant risks to industrial manufacturing systems.
A critical XSS vulnerability in Zitadel's /saml-post endpoint allows account takeovers via malicious scripts. The PoC highlights the need for immediate defensive measures.
zeptoclaw's allowlist and blocklist mechanisms can be bypassed using command injection, argument injection, or file name wildcards, enabling arbitrary command execution. This PoC highlights critical flaws in the project's security model.
The `dnp3times` crate was a malicious, typosquatting attempt that attempted to exfiltrate sensitive `.env` files to a server impersonating `timeapi.io`. The incident highlights risks in Rust crate supply chains and the importance of verifying dependencies.
Cisco has identified two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software that could allow attackers to gain root access, posing a critical risk to network security.
Attackers are sending fake LastPass support emails to steal user vault passwords, posing a critical security risk.
Microsoft has patched a critical issue in Windows 10 that prevented users from accessing the Recovery Environment, which is essential for system repairs and troubleshooting.
A critical zero-click vulnerability in the FreeScout helpdesk platform allows attackers to remotely hijack mail servers without user interaction, posing a severe risk to organizations using the service.
Bitwarden has introduced passkey login support on Windows 11, offering a phishing-resistant authentication method stored in their vault.
PickleScan's blocklist mechanism is bypassed using `pkgutil.resolve_name`, allowing any blocked function to be executed. This flaw enables universal RCE attacks undetected by PickleScan.
PickleScan v1.0.3 fails to block multiple Python stdlib modules enabling RCE, allowing bypass of security scans.
Craft CMS suffers from an authenticated RCE vulnerability due to SSTI in Twig templates, allowing attackers to write malicious scripts to web-accessible directories.