Elektrine lite

← Feed

tomcat

tomcat@infosec.exchange

<p>If olive oil comes from olives 🫒 where does baby oil come from? 🤔 🥸</p>

Posts

  • View post

    🚨 Lunex uses a vulnerable AMD driver to blind security monitoring before stealing browser credentials. The BYOVD chain zeroes kernel callbacks tied to security products, then the stealer collects credentials and cryptocurrency wallet data. 🔗 Read more → https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html

  • View post

    ‼️ WARNING — Citrix NetScaler is facing two unpatched RCE 0-days under active exploitation. Researchers at watchTowr say the flaws are being exploited in the wild. Citrix has not confirmed them or released a patch, affected-version guidance, workaround, or indicators of compromise. What defenders should know now: https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html

  • View post

    ‼️ Mini Shai-Hulud came back without a new attacker update. Two compromised GitHub Actions became reachable again while their tags still pointed to malicious commits, letting downstream workflows resume executing the credential stealer. 🔗 Here&#39;s how the attack reactivated: https://thehackernews.com/2026/09/compromised-github-actions-came-back.html

  • View post

    ‼️ BREAKING - Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores. No login required. No published CVE. No Adobe patch yet. Here&amp;#39;s what to do and how the attack works: https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html

  • View post

    ⚠️ Researchers uncover four previously unreported, persistent programs linked to REVSTEALER. Wallet theft, clipboard hijacking, proxying and mining. The miner can disable Windows Update and add Defender exclusions after elevation. What each program does &amp;gt; https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html

  • View post

    🚨 JSCeal V8 malware can bypass Google authentication using stolen browser cookies. It can also modify Binance, Bybit, and Ledger traffic through a local proxy. How analysts decoded its hidden capabilities: https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html

  • View post

    ‼️ PEEP turns Chrome and Edge into host-level backdoors after compromise. With prior admin or code-execution access, the Smart Bookmarks extension steals session cookies and credentials, then uses Chromium native messaging to run host commands. Read: https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html

  • View post

    🛑 A WeChat call from a contact could take over your account without an answer. Researchers demonstrated the zero-click worm spreading across three iPhone and Android test phones. How the chain worked: https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html

  • View post

    🔥 U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto linked to the scam marketplace. Xinbi then shifted about $2.8 million from USDT to USDD, which lacks USDT’s built-in wallet-freezing feature. Read: https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html

  • View post

    🚨 Thousands of deceptive Android apps are abusing a Google Play trust gap: Early Access apps have no public reviews or star ratings. Fake casino and reward apps are promoted through social ads, including AI-generated celebrity deepfakes. How the scheme works: https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html

  • View post

    🚨 151 million Claude exchanges in one Alibaba-affiliated distillation campaign. Anthropic says it was part of a broader operation involving seven China-based AI labs, with some using proxy networks, fraudulent accounts, and rerouted user requests to harvest Claude capabilities. Inside the operation: https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html

  • View post

    🚨 Attackers chained two JFrog Artifactory flaws to gain admin control and plant backdoors. Only unupdated self-hosted servers were open to that chain. A separate critical auth bypass also drew 406,000 exploitation attempts in one day. How the attacks work: https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html

  • View post

    ⚠️ Nearly 31,000 Twitch users had live OAuth tokens sent to operator-controlled proxies by a malicious browser extension. JeetBot put the credentials in request URLs, exposing them in proxy logs. Older installs keep sending them until updated. Read: https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html

  • View post

    🚨 Fake passkey updates are being used to take over Microsoft cloud accounts. Once inside, threat actors add their own MFA methods and pull data from SharePoint, OneDrive, and mailboxes. Inside the passkey phishing chain → https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html

  • View post

    🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens. It also uses Ethereum smart contracts to rotate C2 and payload locations. How the attack chain works: https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html

  • View post

    ‼️ Attackers are exploiting a critical Issabel Framework flaw. CVE-2026-89026 uses a hard-coded JWT signing key, letting unauthenticated remote attackers forge tokens and execute OS commands as the Asterisk user. A fix is available. How the flaw works: https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html

  • View post

    ‼️ ALERT - Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host. CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights. Read how the escape works → https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html

  • View post

    ‼️ Claude Opus 5 helped three researchers build an image exploit that took over OpenAI&amp;#39;s public help forum server. A flaw in OpenAI&amp;#39;s own login then let them take over staff ChatGPT/Codex accounts and reach an internal code repo — in under 72 hours. Here&amp;#39;s how the chain worked → https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html

  • View post

    🚨 A hard-coded static key in SolarWinds ARM can enable unauthenticated RCE. CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation. Read: https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html

  • View post

    ⚠️ North Korean Jade Sleet is linked to a breach of an Indian IT provider via a DevOps engineer’s Apple Silicon MacBook. FLATROOF and ROOFDECK were found on the system, with capabilities for command execution, remote shell access, persistence, and data theft. Inside the MacBook compromise: https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html

  • View post

    🚨 North Korea’s Contagious Interview campaign compromised 30,000+ devices across 100+ countries and stole at least $10.71M in crypto. Fake job offers and coding tests trigger malware infections; funds or credentials were siphoned from 7,000+ wallets. Inside the chain: https://thehackernews.com/2026/09/contagious-interview-campaign.html

  • View post

    ‼️ Check Point is warning customers about a newly disclosed Security Management Server zero-day exploited in targeted attacks in July. CVE-2026-93616 lets an attacker who can reach the web service upload and run scripts without logging in. A fix landed Sept. 22. Here&amp;#39;s what admins should hunt for: https://thehackernews.com/2026/09/check-point-warns-of-management-server.html

  • View post

    ⚠️ Transparent Tribe is targeting government and defense entities in India and Afghanistan with a new Rust backdoor. RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers. Read more about Operation RapidRust: https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html

  • View post

    🛑 Atlassian&#39;s AI assistant Rovo can be tricked into sending Jira and Confluence data to attackers. Two prompt-injection paths can make Rovo pull data the signed-in user can access and send it to an attacker-controlled server. See how both chains work: https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html

  • View post

    ‼️ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version. XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site&#39;s origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution. Update your WordPress sites ASAP 🠖 https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

  • View post

    🚨 Same URL. Malware for Macs, decoys for scanners. Microsoft tracked over 250 ClickFix domains using browser fingerprinting to decide who sees the fake GitHub download and who sees nothing suspicious. Inside the cloaking system: https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html

  • View post

    🚨 Microsoft 365 Copilot can quietly alter figures during a Word drafting or editing operation, then copy the hidden instructions into the document it creates. That generated file can carry the manipulation into a later Copilot session. Here’s how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html

  • View post

    ‼️ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads. The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE. Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html

  • View post

    ⚠️ Two compromised joyfill npm beta packages run malware as soon as Node.js imports them. No install hook needed. The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit. Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html

  • View post

    🚨 After law enforcement disrupted JackSkid, Dysphoria shifted its IoT botnet C2 to blockchain name services and infected-device relays. Weak Telnet and SSH passwords remain the main way in. Read how the botnet adapted: https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html