π΅οΈ RESEARCH & DEEP DIVES
-
U.S. charges 17 Iranians over Mabna Institute cyber-theft campaign
The U.S. has charged 17 Iranians with conducting a cyber-theft campaign for the IRGC.- The charges apply to 17 Iranian hackers-for-hire employed by the Mabna Institute.
- Targets included 144 U.S. universities, 42 private companies and at least five government agencies.
- Nine defendants allegedly targeted 100,000 professorsβ email accounts and accessed about 8,000.
- The campaign allegedly stole roughly 31 terabytes of research and intellectual property.
- Eight additional defendants allegedly stole HBO data and attempted to extort $6 million in Bitcoin.
π Source: justice.gov Β· π Coverage: cbsnews.com Β· π via @campuscodi@mastodon.social
-
Microsoft Copilot Personal flaws enabled one-click data exfiltration
Varonis found three Microsoft Copilot Personal flaws that enabled one-click data theft.- Microsoft Copilot Personal at copilot.microsoft.com was affected; Microsoft 365 Copilot was not identified as affected.
- The CoSnitch flaws exposed connected mail, calendar, Google Drive, chat history, and Copilot memory data; CVE-2026-24301 tracks the issue.
- An attacker-crafted link combined q= with the undocumented autorun=1 parameter to execute prompts in the victimβs authenticated session.
- Copilot could encode stolen data in base64 and send it through a URL fetch to an attacker-controlled webhook; crafted pages could also poison persistent memory.
π Source: varonis.com Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
Microsoft tracks MacSync Stealer through 30+ rotating C2 domains
Microsoft uncovered more than 30 domains linked to MacSync Stealer infrastructure.- macOS users are targeted by MacSync Stealer, a malware-as-a-service infostealer.
- The malware steals passwords, macOS Keychain data, browser credentials, and cryptocurrency wallet credentials.
- Malvertising delivers a staged zsh loader that downloads and executes additional payloads.
- The loader rotates C2 domains while reusing a static API key and per-build hexadecimal token.
- Observed C2 paths include /curl, /dynamic, and /gate; stolen data is staged as /tmp/osalogging.zip and uploaded in 10 MiB chunks.
π Coverage: microsoft.com Β· π via Microsoft Security Blog
π ADVISORIES
-
π Source for Ransom Busters Poses as Recovery Service, Demands Up to $60,000 β guidepointsecurity.com
-
π Source for Moby go-archive flaw lets Docker archive extraction write outside its target β github.com
π CVEs & KEV
-
CVE-2026-55166 β CVSS 9.9 β Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint al...
-
CVE-2026-47627 β CVSS 9.8 β NVIDIA Triton Inference Server: Critical Path Traversal Leads to DoS
-
CVE-2026-70667 β CVSS 6.3 β Lemur: SSRF protection in certificate revocation checking bypassable via HTTP...
-
CVE-2026-55162 β CVSS 6.3 β Lemur: Post-authentication SSRF via certificate verification - attacker-contr...
-
CVE-2026-55163 β CVSS 6.3 β Lemur: Privilege escalation via PUT /api/1/roles/<id> β non-admin role member...