Cybersecurity Daily: News & Threats
(00:00:00) Blockchain C2, EY Tax Breach & SonicWall Root Access (00:01:17) Microsoft Patch Tuesday 570 Fixes (00:01:55) ViteVenom Blockchain C2 Supply Chain (00:02:45) EY Breach Client Tax Records (00:03:14) WordPress wp2shell RCE Risk (00:03:33) AI Attack Costs and Open-Weight Models (00:03:56) LegacyHive and ModHeader Threats Today's briefing opens with one of the most technically significant stories of the week: UTA0533 exploiting a CVSS 10.0 zero-day chain in SonicWall SMA appliances — CVE-2026-15409 and CVE-2026-15410 — to achieve root access through a WebSocket proxy endpoint and CouchDB path traversal, deploying custom web shells weeks before any patch existed. North Korean-linked group PolinRider pushed seven malicious npm packages impersonating legitimate @vitejs scoped packages, delivering a remote access trojan through a four-tier command-and-control architecture built on public blockchains — Tron, Aptos, and Binance Smart Chain. The infrastructure is effectively unsinkholeable. Domain seizure doesn't apply. This is supply chain attack resilience by design. Ernst and Young confirmed its IT support ticket platform was breached from late March through mid-April, exposing client tax records and investment documents. Detection came nearly three weeks after exfiltration — a blind spot that defines the real risk of third-party privileged platforms. Microsoft's July Patch Tuesday addressed 570 vulnerabilities, two already exploited in the wild: CVE-2026-56164 in SharePoint and CVE-2026-56155 in ADFS. WordPress users face a separate RCE risk via unauthenticated REST API SQL injection across more than 500 million installations. The UK AI Safety Institute benchmarks confirm DeepSeek V4-Pro and GLM-5.2 now match frontier model capabilities for autonomous cyberattacks — at single-digit dollar costs on stripped open-weight models. Also covered: a proof-of-concept Windows User Profile Service exploit bypassing fully-patched July 2026 systems, and the ModHeader Chrome extension — 1.6 million users — pulled after dormant encryption and browsing-history upload code was discovered. This episode includes AI-generated content.
72 jaksot
Kommentit
0Ole ensimmäinen kommentoija
Rekisteröidy nyt ja liity Cybersecurity Daily: News & Threats-yhteisöön!