Suriq - Always on Watch
suriq@infosec.exchange
<p>Practitioner cybersecurity analysis from the Suriq desk.<br />What to patch, what to detect, and why it matters, in plain English. </p><p>Managed security built on Wazuh. suriq.io</p><p><a href="https://infosec.exchange/tags/Cyber" class="mention hashtag" rel="tag">#<span>Cyber</span></a> <a href="https://infosec.exchange/tags/ThreatDetection" class="mention hashtag" rel="tag">#<span>ThreatDetection</span></a> <a href="https://infosec.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a> <a href="https://infosec.exchange/tags/CISA" class="mention hashtag" rel="tag">#<span>CISA</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="tag">#<span>Cybersecurity</span></a></p>
Posts
-
Post #4507951
Close to 800 malicious npm packages ship a cross-platform stealer that runs on import, not at install. Blocked web C2 falls back to DNS. Pulled a new npm dependency this week? Hunt host and DNS logs. https://suriq.io/blog/malicious-npm-packages-dns-c2-stealer #SupplyChain #infosec #cybersecurity
-
Post #4507950
🚨 BREAKING Attackers did not breach Steam, ING or bol. They breached the shipping partner all three share, Ceva Logistics. Customer names, addresses and order details across Europe are exposed. No passwords taken, but expect phishing that quotes your real orders. https://suriq.io/blog/ceva-logistics-breach-customer-data-exposed #SupplyChain #DataBreach #Phishing #infosec
-
Post #4507949
Microsoft ties new StormEncryptor ransomware to China-linked Storm-1175, which breaks in via an N-able N-central auth bypass (CVE-2026-18577). One management console breach reaches every downstream client. Patch to 2026.3.1.7, then hunt. https://suriq.io/blog/storm-1175-stormencryptor-rmm-ransomware #Ransomware #CVE #SupplyChain #Detection
-
Post #4507948
⚠️ PATCH NOW SAP NetWeaver has a critical flaw (CVSS 9.8) that lets a stranger crash the server or leak its memory with no login, through the protocol SAP GUI speaks. Affects SAP NetWeaver AS ABAP; no public exploit yet. Fix: apply SAP&#39;s August kernel patch. (CVE-2026-34265) https://suriq.io/blog/sap-netweaver-diag-unauth-memory-corruption #CVE #DataBreach #infosec #cybersecurity
-
Post #4507947
Undertow, the web server inside Red Hat JBoss, has a pre-login flaw (CVE-2026-15565) that lets anyone crash the server by flooding a WebSocket until it runs out of memory. Affects JBoss EAP 7/8 and Data Grid 8. No patch yet. Fix: disable WebSockets where you can. https://suriq.io/blog/undertow-jboss-websocket-preauth-dos #CVE #Detection #infosec #cybersecurity
-
Post #4507946
Ivanti&#39;s Endpoint Manager has three new high-severity flaws, all fixed in the 2024 SU7 update. One leaks stored database passwords, one lets a user rewrite session recordings, one crashes the agents. Not exploited yet. Patch now. (CVE-2026-18129) https://suriq.io/blog/ivanti-epm-august-2026-su7-management-plane-flaws #CVE #DataBreach #infosec #cybersecurity
-
Post #4507945
Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it leaked to a private repo. It is marked compromised, so past signatures no longer verify. Verify by hand or ship Mozilla RPMs? Import the new key. https://suriq.io/blog/mozilla-firefox-thunderbird-signing-key-revoked #SupplyChain #DataBreach #Linux #infosec
-
Post #4507944
🔴 EXPLOITED North Korea&#39;s Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to take over defense and aerospace PCs. Patched Aug 11, but exploited in the wild first; a kernel rootkit blinded security tools. Run Windows? Update now and hunt. https://suriq.io/blog/lazarus-operation-dream-job-windows-zero-day #CVE #Windows #infosec #cybersecurity
-
Post #4507943
The Fabrik add-on for Joomla has a max-severity flaw (CVSS 10, CVE-2026-67282): a stranger can run code on the server with no login. Every site on Fabrik below 4.6.8 is exposed. Fix: update to 4.6.8 now, then check for stray PHP files. https://suriq.io/blog/fabrik-joomla-unauth-rce-cve-2026-67282 #CVE #infosec #cybersecurity
-
Post #4507942
A Cisco firewall flaw (CVE-2026-20349) lets a stranger crash your ASA or FTD with one crafted request. No login, no workaround, already exploited. When the box reloads, your VPN tunnels drop and its logs go dark. Patch to the fixed build by August 14. https://suriq.io/blog/cisco-asa-ftd-cve-2026-20349-dos-exploited #CVE #CISAKEV #infosec #cybersecurity
-
Post #4507941
🔴 EXPLOITED Gunra ransomware beat multi-factor authentication without phishing anyone. It rewrote a company&#39;s login server so one attacker-chosen code always passed. MFA stayed on; every login looked clean. It gets in via unpatched Fortinet flaws. Patching won&#39;t evict it. https://suriq.io/blog/gunra-ransomware-mfa-auth-backdoor #Ransomware #CVE #Detection #infosec
-
Post #4507940
The &quot;malicious LiteLLM packages&quot; headlines miss it. The real breach was Trivy, the container scanner, poisoned in CI five days earlier. CloudSEK maps 2,500+ orgs of potential exposure, not confirmed breaches. Ran Trivy in March? Rotate your keys. https://suriq.io/blog/trivy-litellm-supply-chain-2500-orgs #CVE #SupplyChain #DataBreach #infosec
-
Post #4507939
Opening a booby-trapped code repository can run an attacker&#39;s commands in editors built on Eclipse Theia (the framework under Arduino IDE 2.x and other tools). A crafted git config runs on folder open, no trust prompt. CVE-2026-19884, CVSS 8.4. Fix: update to Theia 1.70.0. https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884 #infosec #cybersecurity
-
Post #4507938
Encrypted AI reasoning blocks from OpenAI, Anthropic, and Google can be decoded by a weaker model from the same provider. Researchers pulled 182 credentials from 315,320 blocks in public repos. Stop sharing raw AI logs. https://suriq.io/blog/ai-reasoning-traces-leak-api-keys-pii #DataBreach #infosec #cybersecurity
-
Post #4507937
AmnesiaStealer, a new macOS stealer, doesn&#39;t stop at saved passwords. It clones your browser and drives it live, inside your logged-in sessions. Spread via fake GitHub pages that tell you to paste a Terminal command. Reset sessions, not just passwords. https://suriq.io/blog/amnesiastealer-macos-live-browser-hijack #Detection #infosec #cybersecurity
-
Post #4507936
🔴 EXPLOITED macOS Screen Sharing has an auth bypass (CVE-2026-65400) that gives a network attacker root with no password. Apple patched it Aug 6; exposed Macs are already being hit to mine Monero. Update now, or turn Screen Sharing off. https://suriq.io/blog/macos-screen-sharing-cve-2026-65400 #CVE #infosec #cybersecurity
-
Post #4507935
Adobe patched a critical Magento and Adobe Commerce flaw (CVE-2026-71362, CVSS 9.1): a stranger can switch into any customer&#39;s account with no login. Affects all stores through the July 2026 patch level. Fix: apply Adobe bulletin APSB26-92 now. https://suriq.io/blog/magento-adobe-commerce-account-takeover-cve-2026-71362 #CVE #infosec #cybersecurity
-
Post #4507934
GeoServer, the open-source map server, has an unpatched zero-day: unauthenticated SQL injection that can reach remote code execution. No fix yet; probing began within hours. Restrict access and cut the database account&#39;s privileges now. https://suriq.io/blog/geoserver-zero-day-sql-injection-rce-no-patch #CVE #infosec #cybersecurity
-
Post #4507933
Evooo1Bot is a new Linux botnet that exploits internet-facing devices, then turns them into proxies and credential thieves. It targets Confluence, WSO2 and ingress-nginx, not just routers. Watch for rogue services and odd outbound traffic. https://suriq.io/blog/evooo1bot-linux-botnet-servers-socks-relay #CVE #ThreatIntel #Detection #DataBreach
-
Post #4498140
⚠️ PATCH NOW Commvault patched a critical flaw (CVSS 9.2) in CommServe, the brain of its backup platform: an allowlist bypass lets blocked commands run. Affects versions 11.36 to 11.46 on Linux and Windows. Fix: update to the patched release now. (CVE-2026-13737) https://suriq.io/blog/commvault-commserve-command-restriction-bypass #Ransomware #CVE #infosec #cybersecurity
-
Post #4465149
@falken@social.falkensweb.com Hi :) "East-west" just means one of your machines talking to another machine right next to it, NatJack lets a bad neighbor abuse that.
-
Post #4464585
NatJack lets someone who controls one host behind a shared NAT hijack a neighbor's live TCP session and spoof its DNS. Two CVEs, in Windows NAT and the Linux kernel. Patch both, then stop trusting east-west traffic. https://suriq.io/blog/natjack-shared-nat-session-hijack #CVE #Linux #infosec #cybersecurity
-
Post #4431709
A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root when a Linux machine boots over the network. June's fix for the first bug missed it. Only network-booted systems are exposed. Update dracut and rebuild your initramfs. https://suriq.io/blog/dracut-cve-2026-15816-dhcp-root-execution #CVE #Linux #infosec #cybersecurity
-
Post #4393362
SMOKE#SCREEN disables Windows Defender, then installs a validly signed ScreenConnect agent as its backdoor. Your signature allowlist trusts it. The tampering it does first is what gives it away. https://suriq.io/blog/smokescreen-screenconnect-rmm-defender-evasion #ThreatIntel #Detection #Phishing #Windows
-
Post #4376225
An AI system read through 3,915 open-source projects and flagged 14,090 bugs nobody had reported, says Palo Alto's Unit 42. The count isn't the story. The gap between a bug existing and being attacked is shrinking, and the same scan works for attackers. Inventory what you run. https://suriq.io/blog/ai-scanner-14090-open-source-bugs #CVE #infosec #cybersecurity
-
Post #4370741
Device-code phishing rose ~1,500% in 2026. It steals Microsoft 365 tokens after you sign in, so MFA and passkeys do not stop it. Hits Entra ID tenants. Fix: block the device-code flow in Conditional Access, alert on every use. https://suriq.io/blog/device-code-phishing-microsoft-365-token-theft #Detection #Phishing #infosec #cybersecurity
-
Post #4358276
Thermo Fisher patched a flaw that let forensic DNA files be altered before analysis software loaded them (CVE-2026-17583). The fix signs new files only; older archives stay unverifiable. Watch the files your software trusts but never checks. https://suriq.io/blog/thermo-fisher-dna-file-tampering-cve-2026-17583 #CVE #infosec #cybersecurity
-
Post #4353408
Malware can copy the device key behind Google Chrome passkeys and sign in as you, even with two-factor required, Unit 42 showed. The hole: sites that never check the "user verified" bit. Fix: validate that flag server-side. https://suriq.io/blog/chrome-passkey-malware-account-takeover #ThreatIntel #Detection #infosec #cybersecurity
-
Post #4350467
Sharp and Toshiba Tec office copiers sold outside Japan shipped with the device login turned OFF by default. Anyone on the network can read saved scans and edit the address book, no password needed. Fix: enable authentication and patch. (CVE-2026-63563) https://suriq.io/blog/sharp-toshiba-mfp-auth-off-default-cve-2026-63563 #infosec #cybersecurity
-
Post #4276729
Wiz's CosmosEscape reached one platform key in Azure Cosmos DB that could read and write any customer's database, across tenants. Microsoft fixed it, no known impact. Lesson: turn Cosmos key-based auth off where your API allows. https://suriq.io/blog/azure-cosmos-db-cosmosescape-master-key #CVE #CloudSecurity #infosec #cybersecurity