Daily Recap, Cloud and identity security stayed in focus as teams evaluate SSO protections against modern credential attacks, while Microsoft rolled out MAI-Cyber-1-Flash and Google proposed a new threat-actor naming system. Patching and active exploitation were prominent with Apple’s large iOS/macOS fixes, ongoing Fastjson zero-day RCE attempts, and multiple orgs hit by breaches and extortion claims, including Fairlife, Ernst & Young, and reported Dysphoria expansion to 200,000 devices. #SSO #Fastjson #AristaVeloCloud #SmartConsole #CertiGhost #vBulletin #Dysphoria #Fairlife #CocaCola #ShinyHunters #ErnstAndYoung #MCBS #OriginEnergy #Siemens #Schneider #Rockwell #Bahrain #GitHub #PyPI #NVIDIA #OpenSecureAIAlliance #NOOA
Category: Daily Recap
Daily Recap, Organizations are facing a surge in shadow AI agents, with guidance on discovery and security as Nvidia and other tech giants push an AI security alliance to protect expanding AI systems and agent deployments. Meanwhile, attackers continue to evade detection with MedusaHVNC, supply-chain defenses were strengthened by GitHub and PyPI using time-based protections, and new breach disclosures from Coca-Cola and MCBS keep ransomware and large-scale exposure in focus.
#ShadowAI #Nvidia #AIAlliance #MedusaHVNC #GitHub #PyPI #CocaCola #Fairlife #MCBS #Wyden #ZeroTrust #VPN
Daily Recap, Key exploit and access risks dominated today: Fastjson 1.x RCE flaws are actively exploited with no patch available, while a PoC for an authenticated GitLab command-execution bug and Rockwell fixes for Arena code-execution issues were published. Attackers also pushed zero-click Zimbra phishing, used the BlueNoroff Zoom phishing kit, and leveraged Hermes to automate an intrusion against Thailand’s Finance Ministry, alongside data theft tied to Chick-fil-A and sextortion fueled by ShinyHunters leaks.
#Fastjson #GitLab #Rockwell #Arena #Certighost #Zimbra #BlueNoroff #Zoom #ShinyHunters #Hermes #AgentForger #ChickfilA #ThaiFinanceMinistry
Daily Recap, OpenAI patched a ChatGPT Agent flaw that could let attackers forge an AI insider, as industry reporting also described attempts to use OpenAI models to hack Hugging Face systems. AI-driven threats also advanced with Dolphin X and the Hermes AI Agent, while Clop targeted Windchill and FlexPLM, Russian groups exploited a Zimbra zero-day for email theft, and Origin confirmed a data breach after being hacked. #ChatGPT #OpenAI #HuggingFace #DolphinX #Hermes #AegisAI #GoldenChickens #Clop #Windchill #FlexPLM #NotepadPlusPlus #SectopRAT #Zimbra #Origin #ChickfilA #MarcoRubio #Europol #TheCom #Cavalier #LinuxKernel
Daily Recap, Microsoft 365 experienced a service outage impacting Teams and SharePoint, while Exchange Online also faced a mailbox quarantine issue during active repair. Multiple Linux and application risks were reported, including the RefluXFS root-privilege flaw and the Windmill authentication-bypass data exposure being exploited, alongside new threats such as msaRAT routing C2 through Chrome and Edge. #Microsoft365 #Teams #SharePoint #ExchangeOnline #RefluXFS #root #Ubuntu #snap-confine #Windmill #Chrome #Edge #msaRAT
Daily Recap, Two reports warned that an Adobe Chrome extension with 300M installs could let websites access private WhatsApp chats and steal user data, while CISA ordered urgent patching for the actively exploited Langflow RCE and noted abuse of critical SharePoint RCE to steal machine keys. Attackers also targeted WordPress via wp2shell flaws to deploy web shells, and the Anubis ransomware group claimed the Coca-Cola Fairlife incident as Chick-fil-A disclosed a breach linked to credential stuffing. #Adobe #ChromeExtension #WhatsApp #Langflow #SharePoint #wp2shell #WordPress #Anubis #CocaColaFairlife #ChickfilA
Daily Recap, Malware reports highlighted HollowGraph’s Microsoft 365 Calendar/Graph-based C2 evasion and FakeGit’s use of 7,600 GitHub repositories to deliver SmartLoader, alongside SonicWall SMA1000 zero-days exploited for weeks before patching. On the exposure and incident front, ServiceNow exploitation appeared within days, Qilin ransomware targeted Palo Alto GlobalProtect, and multiple organizations—including Estée Lauder and Clover Health—reported breaches tied to Oracle E-Business and other issues. #HollowGraph #Microsoft365 #GraphC2 #FakeGit #SmartLoader #SonicWallSMA1000 #ServiceNow #PaloAltoGlobalProtect #Qilin #EsteeLauder #OracleEBusiness #CloverHealth
Daily Recap, Hugging Face reported that an autonomous AI agent contributed to a breach exposing internal datasets and credentials, while Ernst & Young disclosed a data breach impacting personal and financial information. In exploited-vulnerability news, attackers are leveraging critical ServiceNow code execution flaws, WP2Shell WordPress issues, and a new 7-Zip flaw involving XZ archives, alongside updates including Microsoft’s KB5121767 for affected Dell PCs and Chrome 150 patches for severe memory-safety bugs.
#HuggingFace #ErnstAndYoung #ServiceNow #WP2Shell #7Zip #XZ #KB5121767 #Dell #ViPNet #AI_SOC
Daily Recap, Iran is reportedly tracking US military phones as new macOS threats such as CrashStealer and ClickLock appear to steal credentials, while OkoBot reportedly delivered 20 payloads aimed at data and crypto theft. Shortly after disclosure, attackers began exploiting a SharePoint vulnerability, alongside reports of active abuse of Fortinet flaws, while Japan’s Nichirei experienced an operational disruption and Fairlife ransomware tied to Coca-Cola’s supplier halted US dairy production. #CrashStealer #ClickLock #OkoBot #SharePoint #Fortinet #Nichirei #CocaCola #Fairlife #TfL #ScatteredSpider
Daily Recap, Major vendors including Splunk, Zoom, F5, Trend Micro, Tanium, ESET, Tenable, Firefox, Chrome, Adobe, and VMware shipped patches for multiple critical issues such as account takeover and code-execution vulnerabilities, while CISA ordered U.S. federal agencies to remediate an actively exploited Oracle flaw and addressed exploited SharePoint weaknesses. Active campaigns also made headlines as Russian actors pushed Starland by trojanizing WebEx and Zoom installers, and Spirals ransomware reportedly encrypted a victim network in under 24 hours. #Splunk #Zoom #F5 #TrendMicro #Tanium #ESET #Tenable #Firefox #Chrome #Adobe #VMware #CISA #Oracle #SharePoint #Starland #WebEx #Spirals #SonicWall #UEFI #SecureBoot #LegacyHive #OkoBot #Ledger #Trezor #GoogleGeminiCLI #TuxBot #AsyncAPI #npm #23andMe #ScatteredSpider #TransportforLondon #ChromeSync
Daily Recap, Microsoft’s record July Patch Tuesday delivered 622 fixes, including 2–3 actively exploited zero-days, alongside Windows 11 cumulative updates and an extended security update for Windows 10 as organizations rush to remediate. SAP, Adobe, and VMware pushed urgent high-severity patches, SonicWall warned SMA1000 flaws are being exploited as zero-days, CISA urged updates for actively exploited SharePoint issues, and security investigations targeted cybercrime infrastructure linked to ransomware enablers as phishing and malvertising campaigns continued to evolve. #Microsoft #Windows11 #Windows10 #SAP #Adobe #VMware #NetWeaver #ColdFusion #VMwareAvi #AviLoadBalancer #SonicWall #SMA1000 #SharePoint #ProgressShareFile #FirstVPN #ClickFix #LastPass #Bitwarden #Artlist #EDR #BindLink #NATO #GoldEagle
Daily Recap, Microsoft 365 users are facing new phishing kits that evade MFA, and Microsoft Entra ID is moving toward passkeys as the default authentication method starting in September. In other reporting, macOS users should watch for CrashStealer impersonation tactics, supply-chain backdoors were found in Jscrambler npm packages via infostealer, and CISA flagged actively exploited Joomla RCE flaws while agencies warned of Russian targeting of critical-infrastructure routers. #Microsoft365 #MicrosoftEntraID #Passkeys #EvadeMFA #PhishingKits #CrashStealer #Gatekeeper #Jscrambler #npm #infostealer #SAP #NetWeaver #CommerceCloud #CISA #Joomla #RCE #Russian #Cisco #CriticalInfrastructureRouters
Daily Recap, US and allied agencies warned that Russian actors are targeting critical infrastructure, while the EU and UK followed with sanctions and charges connected to cyber activity and call-spoofing platforms. Meanwhile, RedHook updated its Android malware to use Wireless ADB for shell access, a RabbitMQ vulnerability threatens enterprise messaging environments, and sector M&A stayed active with governance pressure growing around AI-generated code security risk oversight. #Russian #RedHook #WirelessADB #RabbitMQ #JesseMcGraw #GhostExodus
Daily Recap, Two key themes dominated today: attackers are targeting AI and software supply chains, including Ghostcommit’s prompt-injection images and a GitHub compromise at Injective Labs that pushed wallet-key-stealing npm packages. Critical patching also remains urgent, with vulnerabilities in Zimbra, ShareFile, U-Boot, and Gitea along with broader pressure on healthcare, privacy, and enforcement efforts.
Daily Recap, Threat activity highlighted targeting of a Pakistani police force by China- and India-linked hackers, new Helix SharePoint-related vishing theft tactics, and GigaWiper’s Windows backdoor that blends disk wiping, fake ransomware, and spyware. Patch and response updates included Zimbra’s critical XSS fix, Palo Alto Networks’ 13 vulnerability updates, Microsoft’s additional Windows security expectations plus OWA Light retirement, and npm supply-chain hardening via Injective SDK and npm 12’s install-script changes, while BlackCat and DigitalMint cases progressed through sentencing. #China #India #Pakistani #Helix #SharePoint #Okta #Microsoft365 #Forg365 #GigaWiper #GitHub #InjectiveSDK #Zimbra #XSS #PaloAltoNetworks #Microsoft #OWALight #ExchangeServer #npm12 #BlackCat #DigitalMint #INTERPOL #NSA #TailoredAccessOperations