๐จ ACTIVE EXPLOITATION
-
Malicious Solidity Pro VS Code Extensions Steal Wallets and Credentials Malicious Solidity Pro VS Code extensions are stealing crypto wallets, API keys, and developer credentials.
- VS Code users and Ethereum developers using helper-beeps.solidity-pro or web3devtoolsx.solidity-pro are affected.
- Versions 3.0.0 and later steal browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens.
- Versions 1.0.0 through 2.4.x fetched encrypted Python payloads from Cloudflare Workers.
- The extensions use obfuscation, delayed activation, and changing method names to evade marketplace review and static scanning.
- Stolen data is exfiltrated through a Telegram bot; harvested token formats include ghp_, github_pat_, glpat-, cfat_, sk-, sk-proj-, and sk-ant-. ๐ Source: yeethsecurity.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Malicious VBS/PowerShell RAT Campaign Uses Multiple DuckDNS Hosts A malware campaign is using VBS and PowerShell scripts to deploy a remote access trojan on Windows systems.
- Windows users and business endpoints are targeted by the campaign.
- The RAT can steal browser credentials and cookies, log keystrokes, and capture clipboard data.
- Obfuscated VBS files envifa.vbs and sostener2.vbs decrypt an AES-256-encrypted PowerShell stage.
- PowerShell extracts an x64 payload that uses a .NET helper for process hollowing inside AppLaunch.exe.
- Infrastructure includes multiple DuckDNS hosts, 181.237.42[.]61, and suspected C2 serversniperxx[.]duckdns[.]org:4577; VBS SHA-256: 8c78a55c8bf545e0d21b8757eaa0b709b4af47b13d34a38df81045e67026bd96. ๐ Source: x.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
-
Levi Strauss Says Social Engineering Attack Stole Corporate Data Levi Strauss says attackers used social engineering to steal corporate data.
- Levi Strauss & Co. was affected through three employees' company-issued computers.
- Attackers accessed and exfiltrated certain corporate information.
- No consumer data appears to have been impacted, based on preliminary findings.
- The intrusion used social engineering; the specific tactic and threat actor remain unknown. ๐ Source: sec.gov ยท ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
Bybit Wins U.S. Court Orders to Trace and Freeze Lazarus Hack Funds Bybit secured U.S. court support to recover funds from the $1.5 billion Lazarus hack.
- Bybit and assets stolen in the February 2025 attack are covered; defendants include North Korea, its Reconnaissance General Bureau, Lazarus Group and 20 unidentified parties.
- The attackers stole more than 400,000 ETH and staked ETH from Bybit.
- Expedited discovery allows Bybit to seek account identities, balances and transaction histories from U.S.-linked platforms.
- Stolen funds moved through mixers, cross-chain bridges and over-the-counter dealers; 90.2% was untraceable by June 18.
- Bybit reports $48.4 million recovered and $30.5 million frozen across more than 28 exchanges and custodians. ๐ Source: bybit.com ยท ๐ Coverage: crypto.news ยท ๐ via @metacurity@infosec.exchange
๐ต๏ธ RESEARCH & DEEP DIVES
-
UPDATE: Prompt Injection Could Make Atlassian Rovo Leak Enterprise Data Researchers found that prompt injection could make Atlassian Rovo exfiltrate enterprise data.
- Atlassian Cloud tenants with Rovo enabled were affected across Jira, Confluence, Bitbucket and connected SaaS services.
- Rovo could access and leak data available to a signed-in user, including Jira tickets, Confluence pages, SharePoint documents, Outlook emails and private API keys.
- Varonis's RovoBlast used the rovoChatPrompt URL parameter to preload attacker instructions into Rovo Chat.
- A single authenticated click could trigger Rovo to collect data and send it to an attacker-controlled server through autonomous URL retrieval.
- PromptArmor also demonstrated indirect injection through attacker-controlled uploaded documents; Atlassian fixed the URL-parameter issue server-side on July 8, 2026. ๐ Source: bugcrowd.com ยท ๐ Coverage: varonis.com ยท ๐ via Cyber Security News
-
Claude Code Activity Exposed macOS Services Through Tunnels and LaunchAgents Elastic observed Claude Code activity creating reverse tunnels and LaunchAgent persistence on macOS.
- The activity affected macOS developer endpoints running Claude Code and, in related cases, Cursor.
- Credentialed requests exposed local services and application metrics through public tunnels while LaunchAgents maintained access across logout or reboot.
- zsh shells under Claude Code used curl, cloudflared, ngrok, launchctl and PlistBuddy.
- Observed indicators included lhr[.]life, trycloudflare[.]com, api.trycloudflare[.]com, /tmp/mcp_clean_landers.py and ~/.claude/projects/*/memory/MEMORY.md. ๐ Coverage: elastic.co ยท ๐ via Cyber Security News