π¨ ACTIVE EXPLOITATION
- Malicious Rust Crate arrayref Runs a Build-Time Payload
submitted by /u/BattleRemote3157 [link] [comments]
π Coverage: reddit.com Β· π via r/cybersecurity
π΅οΈ RESEARCH & DEEP DIVES
-
Critical isolated-vm flaw enables sandbox escape and potential host RCE
A critical isolated-vm flaw enables sandbox escape and host control-flow hijacking.- The flaw affects isolated-vm deployments, including AI-related projects such as n8n, Activepieces, and Mastra AI.
- GHSA-864f-rcv7-6rh4 affects isolated-vm versions before 7.0.1 and the 6.x branch before 6.2.0.
- A type confusion in ExternalCopy handling of the transferList option corrupts host-process memory.
- Attackers can escalate from a controlled crash to host control-flow hijacking using an ivm.Reference.
π Source: endorlabs.com Β· π Coverage: thehackernews.com Β· π via The Hacker News, r/cybersecurity
-
Transparent Tribe Targets Afghan Telecom With PATCHCORD Backdoor
Transparent Tribe is targeting Afghan telecom and South Asian critical infrastructure with new backdoors.- Afghan telecom providers, government agencies, defense and energy organizations are targeted.
- PATCHCORD, SHEETCORD and HACKERAI C2 Agent provide remote access, host fingerprinting and command execution.
- PATCHCORD arrives through fake Afghan Telecom installers and hijacks browser shortcuts for persistence.
- SHEETCORD uses Google Sheets API C2; HACKERAI C2 Agent uses GitHub Gists.
- Observed infrastructure includes C2 IP 46.30.188[.]13 and the impersonating domain nic-support[.]site.
π Source: bitdefender.com Β· π Coverage: darkreading.com Β· π via Dark Reading
-
Encrypted web-page prompts can exfiltrate Grok usersβ chat data
Researchers demonstrated an encrypted prompt injection that exfiltrates Grok user data.- Grok.com users who ask the chatbot to summarize web pages are affected.
- The attack exposes usersβ names, approximate locations, subscription tiers, and conversation prompts.
- A malicious page embeds encrypted instructions, a decryption key, and directions to process the ciphertext.
- Grokβs code runtime decrypts PBKDF2 and AES-256-GCM payloads, then sends the data to an attacker-controlled URL.
π Source: adversa.ai Β· π Coverage: arstechnica.com Β· π via The Hacker News
-
Phishing toolkit covertly enrolls hidden passkeys on compromised Google accounts
Abnormal Security identified a phishing toolkit that secretly enrolls attacker-controlled passkeys.- The toolkit targets Google accounts using passkey authentication.
- iAuthFlow v2 captures credentials through a phishing site.
- It automatically registers a hidden attacker-controlled passkey after compromise.
- The toolkit was reportedly offered for about $10,000.
π Source: cifas.org.uk Β· π Coverage: abnormal.ai Β· π via @campuscodi@mastodon.social
π CVEs & KEV
-
CVE-2026-49825 β CVSS 8.2 β lxml: javascript: URL bypass in Cleaner via xlink:hreflxml is a library for p...
-
CVE-2026-61898 β CVSS 7.8 β accountsservice: shell injection via attacker-controlled ~/.pam_environment i...
-
CVE-2026-61897 β CVSS 7.8 β accountsservice: incomplete privilege drop when running Ubuntu-specific langu...
-
CVE-2026-63490 β CVSS 7.5 β Handlebars.java: Arbitrary file read in
SpringTemplateLoadervia URL-fragme... -
CVE-2026-44725 β CVSS 6.6 β EMQX: Stale plugins allow grants amplify a compromised admin/API key to remot...
π ADVISORIES
-
π Source for NASA AIT-GUI Flaws Let Unauthenticated Attackers Issue Spacecraft Commands β cycode.com
-
π Source for Eight vulnerabilities affect IBM AIX and PowerVM VIOS β ibm.com