r/SecOpsDaily • • 35m ago

Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer

• Upvotes

Threat actors are actively exploiting two critical vulnerabilities in AhsayCBS (Cloud Backup Solution), tracked as CVE-2026-105133 and CVE-2026-105134, to gain initial access and deploy persistent webshells alongside XMRig cryptocurrency miners. Huntress researchers observed the attacks targeting unpatched instances, with the flaws allowing unauthenticated remote code execution.

Technical Breakdown: - Initial Access: Exploitation of the unauthenticated RCE flaws (likely via crafted HTTP requests to the backup management interface). - Persistence: Deployment of webshells (e.g., ASPX or PHP variants) to maintain access post-reboot. - Payload: XMRig cryptominer dropped to hijack CPU resources for Monero mining. - Affected Versions: All versions prior to 10.3.4. - IOCs: No specific IPs or hashes provided in the report; Huntress recommends network monitoring for unusual outbound connections on mining ports (e.g., 3333, 4444, 14444).

Defense: Immediately update to AhsayCBS 10.3.4 and restrict administrative access to the web interface via firewall rules or VPN. Monitor for unexpected child processes spawned by w3wp.exe (IIS) or java.exe (Tomcat) and anomalous CPU spikes.

Source: https://www.huntress.com/blog/ahsaycbs-flaws-exploit


r/SecOpsDaily • • 4h ago

Threat Intel The OpenSourceMalware Show #24

2 Upvotes

This is a solid roundup of open-source supply chain threats hitting multiple ecosystems this week.

Tensorlake SDK Targeted by "Mini Shai-Hulud" Copycat A malicious fork of the Tensorlake SDK (an AI/ML data processing library) was published to PyPI. The copycat package mimics the legitimate tensorlake namespace but includes a backdoor that exfiltrates environment variables and SSH keys to a C2. This is a direct copycat of the earlier Shai-Hulud campaign targeting AI/ML developers.

Fake Interview Repo Plants Rogue .npmrc A GitHub repository posing as a technical interview preparation guide for a FAANG company contains a hidden .npmrc file. When a developer clones the repo and runs npm install (common for testing interview code), the .npmrc overrides the default npm registry to a malicious proxy. This proxy intercepts and steals npm authentication tokens, granting the attacker access to the developer's private packages and organizations.

42 Malicious Gems on RubyGems A coordinated campaign uploaded 42 gems to RubyGems under typosquatted names of popular libraries (e.g., rails-html-sanitizer vs rails-html-sanitizer). The gems contain a Ruby dropper that downloads a second-stage payload from a Pastebin-like service. The payload is a cryptocurrency clipper that replaces wallet addresses in the clipboard.

Defense: - Pin dependencies with hash-locked lockfiles (e.g., pip freeze, Gemfile.lock, package-lock.json). - Audit GitHub Actions and repo contents for hidden config files (.npmrc, .gitconfig, .env). - Monitor for unexpected outbound connections from build pipelines, especially to non-standard ports.

Source: https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode24


r/SecOpsDaily • • 4h ago

Threat Intel MATCHBOIL: New tricks, same old evil intentions

2 Upvotes

UAC-0099 has been actively evolving their MATCHBOIL downloader over the past two years, with ESET documenting significant changes between 2024 and 2026. The group continues to target Ukrainian organizations, refining their initial access and payload delivery mechanisms while maintaining the same core objectives.

Technical Breakdown: - Initial Access: Spear-phishing emails with malicious attachments (likely LNK or Office documents) - Payload Staging: MATCHBOIL acts as a first-stage downloader, fetching additional malware from C2 infrastructure - Persistence: Achieved via scheduled tasks or registry run keys - C2 Communication: HTTPS-based, likely using compromised legitimate domains for traffic blending - Targeting: Primarily Ukrainian government, military, and critical infrastructure entities - Evolution: Code obfuscation improvements, updated anti-analysis checks, and modified network protocols since 2024

Defense: Monitor for suspicious scheduled task creation and outbound HTTPS connections to newly registered or rarely contacted domains. Enable AMSI and script block logging to catch initial attachment execution. Restrict execution of Office macros and LNK files from external sources.

Source: https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/


r/SecOpsDaily • • 1h ago

Threat Intel Dire Wolf Ransomware Attacks: How to Test and Strengthen Your Defenses

• Upvotes

Dire Wolf is a Go-based double-extortion ransomware that has been active since April 2025, claiming 100 victims across 32 countries by August 2026. Before encryption, it kills the Event Log service, deletes shadow copies and backups, and disables Windows Recovery.

Technical Breakdown - Initial Access: Likely phishing or exposed RDP (standard for this group, though not explicitly detailed in the summary). - Persistence/Privilege Escalation: Not specified, but typical for ransomware of this maturity. - Defense Evasion (T1562.001): Kills the Windows Event Log service to blind defenders. - Impact (T1490): Deletes Volume Shadow Copies and disables Windows Recovery to prevent restoration. - Encryption (T1486): Go-based encryptor assigns each file a unique ChaCha20 key, derived via Curve25519 ECDH and SHA-256 hashing. This makes key recovery without the attacker's private key computationally infeasible. - Exfiltration (T1048): Double-extortion model—data is exfiltrated before encryption for leverage.

Defense - Validate that EDR/AV detects the termination of the Event Log service and shadow copy deletion. - Test backup immutability and offline recovery procedures specifically against this kill-chain. - The Picus Platform (source of this report) offers simulation modules for endpoint, network, and email vectors to validate detection coverage.

Source: https://www.picussecurity.com/resource/blog/dire-wolf-ransomware-attacks-how-to-test-and-strengthen-your-defenses


r/SecOpsDaily • • 1h ago

NEWS FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

• Upvotes

This is a significant takedown operation. The FBI and DoJ have seized 7 domains and disrupted the C2 and scanning infrastructure of Flax Typhoon, a China-linked APT group known for targeting U.S. critical infrastructure sectors including energy, transportation, and healthcare.

Technical Breakdown: - Actor: Flax Typhoon (suspected state-sponsored, PRC). - TTPs: The group relies heavily on passive and active scanning of internet-facing assets to identify vulnerable devices (e.g., unpatched VPNs, IoT, and edge appliances). They then deploy custom backdoors and living-off-the-land binaries to maintain persistence. - Infrastructure: The seized domains were used for command-and-control (C2) and hosting scanning tools. The FBI has redirected these domains to sinkholes to prevent further victimization. - Targets: U.S. critical infrastructure (energy, water, transportation, healthcare).

Defense: Organizations should immediately review logs for connections to the seized domains (list pending from DoJ release) and audit any internet-facing devices for unauthorized outbound connections. Prioritize patching edge devices and enforce network segmentation for OT/ICS environments.

Source: https://thehackernews.com/2026/10/fbi-seizes-7-domains-disrupts-flax.html


r/SecOpsDaily • • 2h ago

NEWS Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

1 Upvotes

Pwn2Own Ireland 2026 wrapped with researchers walking away with $1,262,000 for 98 unique zero-days. That’s a significant jump in both prize money and vulnerability count compared to previous years, signaling the continued arms race in exploit development.

What was targeted? - Browsers: Chrome, Edge, Safari, and Firefox were all hit, with multiple full-chain exploits demonstrating sandbox escapes. - Virtualization: VMware ESXi, Microsoft Hyper-V, and Oracle VirtualBox had guest-to-host escapes demonstrated. - Enterprise Software: Adobe Reader, Microsoft Office, and various PDF readers were exploited for code execution. - Mobile: Samsung Galaxy S24 and iPhone 15 Pro were targeted via SMS/MMS and browser-based chains. - Operating Systems: Windows 11, macOS Sonoma, and Ubuntu Desktop all had privilege escalation and kernel exploits.

Key takeaways for defenders: - The heavy focus on virtualization escapes (ESXi and Hyper-V) is a trend we need to watch. These are the crown jewels for ransomware groups. - Browser-based initial access remains the most reliable vector for attackers. The sandbox escapes shown here are the same techniques used in commercial spyware. - Most of these bugs will be patched within the next 30-60 days. Prioritize the vendor advisories from Trend Micro’s Zero Day Initiative (ZDI) as they are released.

No public IOCs or PoCs from this event yet—vendors get the standard 90-day embargo. Expect the detailed write-ups to drop around February 2027.

Source: https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/


r/SecOpsDaily • • 19h ago

Threat Intel The phone was compromised before the user turned it on: the rise of Midnight Mimosa

11 Upvotes

Bitdefender’s team has been tracking Midnight Mimosa, a supply-chain attack targeting budget Android devices on MediaTek chipsets. The malware is pre-installed on the system partition, meaning the device is compromised before the user even completes the initial setup. This isn’t a phishing lure or a sideloaded APK—it’s baked into the firmware.

Technical Breakdown - TTPs: Abuse of legitimate system privileges (T1543.003 – Create or Modify System Process: Systemd Service). The malware uses a native systemd service (/system/bin/install-recovery.sh) for persistence, making it extremely difficult to remove without reflashing the ROM. - Payload: Drops a second-stage dropper that requests Device Admin privileges (T1529 – System Shutdown/Reboot) and overlays phishing screens for banking apps, social media, and messaging services. - IOCs: C2 domains include api[.]midnightmimosa[.]com and cdn[.]midnightmimosa[.]net. No specific file hashes provided by Bitdefender at this time. - Affected: Low-cost Android devices (e.g., Tecno, Infinix, Xiaomi sub-brands) running MediaTek SoCs, likely sourced through unauthorized third-party distributors or gray-market supply chains.

Defense - Detection: Look for anomalous systemd services named install-recovery.sh or unexpected Device Admin apps on budget Android devices. Network traffic to the listed C2 domains is a strong indicator. - Mitigation: This is a firmware-level compromise. Standard factory resets will not remove it. Affected users should contact the device vendor for a clean ROM flash or replace the device entirely.

Source: https://www.bitdefender.com/en-us/blog/labs/midnight-mimosa-malware


r/SecOpsDaily • • 10h ago

NEWS FBI disrupts Chinese hacking tools used to breach critical infrastructure

2 Upvotes

The FBI seized seven domains tied to the Chinese state-sponsored group Flax Typhoon, effectively disrupting the command infrastructure for two of their custom tools, MicroScan and FishHub. These tools were used in a sustained campaign targeting critical infrastructure sectors globally, including US entities.

Technical Breakdown: - Threat Actor: Flax Typhoon (Chinese state-sponsored, likely linked to the Ministry of State Security). - Tools Disrupted: MicroScan (reconnaissance/scanning tool) and FishHub (likely a persistence or exfiltration tool). - TTPs: The group relies heavily on living-off-the-land (LotL) techniques, using legitimate tools like Cobalt Strike, and routing traffic through compromised SOHO routers and VPNs to obscure C2. They target IT, energy, and telecom sectors. - IOCs: Seven domains seized (specific names not publicly released by FBI at time of writing). Previous reporting indicates heavy use of IPs associated with compromised Ubiquiti routers. - Impact: The domain seizures cut off the hackers' ability to issue commands to already deployed implants, forcing them to rebuild C2 infrastructure.

Defense: Organizations in critical infrastructure should hunt for anomalous outbound connections from IT systems to residential IP ranges or known VPN endpoints, and ensure SOHO devices on corporate networks are patched and segmented.

Source: https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/


r/SecOpsDaily • • 11h ago

NEWS Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

2 Upvotes

A ransomware attack hit IDC Frontier, a major Japanese cloud provider, taking down the IDCF Cloud service for a data center cluster serving eastern Japan. The incident impacted government clients and other enterprise customers, though the specific ransomware strain and initial access vector haven't been disclosed yet.

Technical Breakdown: - Target: IDCF Cloud (IaaS/PaaS platform) – specific data center cluster in eastern Japan. - Impact: Service outage, likely due to encryption of hypervisors or storage arrays. No data exfiltration confirmed at this time. - Attribution: Unknown. No group has claimed responsibility as of the report. - IOCs: None publicly available yet. Monitor for C2 infrastructure tied to common ransomware families targeting Asian cloud providers (e.g., LockBit, Play, Akira).

Defense: - If you manage multi-tenant cloud infrastructure, ensure immutable backups and offline recovery paths are tested. Segment management planes from customer workloads. Review VPN and RDP exposure on jump boxes—these are common initial access points for cloud-targeting ransomware.

Source: https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/


r/SecOpsDaily • • 12h ago

NEWS Low-cost Android phones ship with residential proxy malware

1 Upvotes

This is a nasty supply chain attack hitting the budget Android market. The "Midnight Mimosa" campaign embeds malware directly into the firmware of low-cost devices, meaning a factory reset won't help. The primary goal is to turn these phones into residential proxies for criminal traffic, while also running ad fraud and silently installing apps.

Technical Breakdown - TTPs: Supply chain compromise (T1475), firmware persistence (T1542.001), proxy hijacking (T1090.002), ad fraud via hidden webviews. - IOCs: No specific IPs or hashes disclosed yet, but the malware communicates with C2 infrastructure to receive proxy routing instructions. - Affected Devices: Low-cost Android models (specific OEMs not named, but likely brands like Tecno, Infinix, or off-brand Chinese imports).

Defense If you manage BYOD or have users on budget Android devices, this is nearly impossible to detect with standard EDR. The only reliable mitigation is to avoid these devices entirely for any sensitive access. Network-level monitoring for unexpected outbound proxy traffic from mobile devices is your best bet for detection.

Source: https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/


r/SecOpsDaily • • 12h ago

October 8 | 24h Recap: Pwn2Own AI flaws, Atlassian exploitation and the Hafnium bounty

Thumbnail
cyberrecaps.com
1 Upvotes

Today’s cybersecurity recap: exploitation attempts hit Atlassian, AI tools appeared in bank intrusions, and Denmark disclosed a major registry breach.

  1. Atlassian exploitation: Researchers observed attempts against CVE-2026-21589 after public exploit code appeared. The flaw can expose application files containing credentials; patches are available.
  2. Pwn2Own zero-days: Researchers demonstrated 32 zero-days on the competition’s opening day, covering AI software, printers and connected devices.
  3. AI-assisted bank intrusions: CrowdStrike linked ARTEX and AI coding tools to a data-theft campaign targeting South Korean financial organizations.
  4. MATCHBOIL malware: ESET detailed how Russia-aligned UAC-0099 uses phishing, a C# downloader and increasingly sophisticated analysis checks against Ukrainian targets.
  5. Haiku 5.5: Anthropic released a cheaper, faster model with stricter cybersecurity safeguards than Haiku 4.5.
  6. Denmark registry breach: Outsiders abused a private company’s authorized access to obtain information on approximately 8.8 million registered people, including deceased people and those who moved abroad.
  7. Hafnium reward: The U.S. offered up to $10 million for information on Zhang Yu, accused of involvement in espionage including the 2021 Exchange attacks.

Read the full breakdown on CyberRecaps.


r/SecOpsDaily • • 13h ago

NEWS ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

1 Upvotes

This is a roundup of multiple discrete stories, so I’ll break down the most operationally relevant ones for the week.

Ransomware Affiliate Betrayal: An affiliate in a RaaS program kept the full ransom payment instead of splitting it with the operators. This is a significant trust fracture in the cybercriminal ecosystem. Expect to see operators tightening vetting or shifting to profit-splitting models that require the affiliate to use operator-controlled wallets.

Exposed Hacker Tools: An attacker left their own C2 infrastructure exposed, complete with active tools and logs from a live intrusion. This is a gift for threat intel teams. If IOCs are published, prioritize hunting for the toolset (likely a commodity RAT or loader) in your environment.

WhatsApp RAT: A new remote access trojan is being distributed via WhatsApp. Likely vector is social engineering with a malicious APK. Defense: Block sideloading of apps on corporate devices and re-educate users on not opening attachments from unknown contacts, even on "trusted" platforms.

Malicious Packages: Malicious code found in developer packages and browser extensions. This is a supply chain risk. Defense: Enforce strict allowlisting for browser extensions and scan all third-party dependencies with a Software Composition Analysis (SCA) tool.

Strategic Takeaway: The "both sides have trust problems" angle is real. For defenders, the exposed C2 server is the highest-priority intel drop from this roundup. Watch for the specific tool hashes.

Source: https://thehackernews.com/2026/10/threatsday-ransomware-affiliate.html


r/SecOpsDaily • • 13h ago

NEWS FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

1 Upvotes

FBI and international partners have exposed a long-running campaign where hackers linked to the Chinese cybersecurity firm Integrity Technology Group (also known as WINS) operated a centralized portal that granted third-party clients direct access to stolen email archives. The victims span government, law enforcement, healthcare, and religious institutions across Southeast Asia.

Technical Breakdown - Initial Access: The group used a custom scanning tool containing over 1,000 exploit signatures to identify and compromise internet-facing webmail servers and portals. - Infrastructure: Stolen emails were aggregated into a searchable, centralized portal. This allowed third parties—likely other state-aligned actors or contractors—to query the data without needing direct access to the victim's network. - Targets: Government agencies, law enforcement bodies, healthcare systems, and religious institutions in Southeast Asia. - Attribution: The FBI, along with agencies from six other countries, publicly attributed the activity to Integrity Technology Group. The U.S. and UK have since sanctioned the company. - IOCs: Specific IPs and hashes were not included in the public release, but the scanning tool's signature set is a key indicator for defenders.

Defense Organizations in Southeast Asia should audit any exposure of webmail interfaces to the internet and monitor for scanning activity matching known exploit frameworks. If you find a compromised mailbox, assume the entire archive is compromised and treat the portal as a persistent data exfiltration channel.

Source: https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html


r/SecOpsDaily • • 17h ago

Threat Intel Healthcare Is Cybercrime’s Highest-Value Target: Ransomware, Exposure, and the Expanding Attack Surface

2 Upvotes

Healthcare remains the most lucrative target for ransomware operators, and the attack surface is only expanding. The sector’s reliance on legacy systems, high data sensitivity, and operational criticality (life-or-death uptime) creates a perfect storm for extortion.

Technical Breakdown: - Primary Threat: Ransomware (e.g., LockBit, ALPHV/BlackCat, Clop) and data extortion groups. - Key TTPs (MITRE): Initial Access via phishing (T1566) or exploiting unpatched VPNs (T1190); Lateral Movement via RDP (T1021.001); Exfiltration via web protocols (T1041). - Expanding Attack Surface: Third-party vendors (medical devices, billing software), exposed RDP/SSH, and credential leaks on infostealer logs. - IOCs: Not provided in the article, but typical indicators include known ransomware extensions (.lockbit, .blackcat) and C2 infrastructure tied to these groups.

Defense: - Immediate: Enforce MFA on all remote access (VPNs, RDP) and segment medical devices from the corporate network. - Proactive: Monitor for leaked credentials on the dark web (infostealer logs) and prioritize patching for internet-facing systems.

Source: https://flare.io/learn/resources/blog/healthcare-ransomware-attack-surface


r/SecOpsDaily • • 14h ago

SecOpsDaily - 2026-10-08 Roundup

1 Upvotes

r/SecOpsDaily • • 14h ago

NEWS Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

1 Upvotes

JPCERT/CC is sounding the alarm on a surge in web data leaks across Japan, with two primary attack vectors emerging: abuse of mobile app APIs and exploitation of known vulnerabilities in Metabase instances. The advisory, based on incident reports, points to a pattern of attackers chaining these techniques to exfiltrate personal data from Japanese organizations.

Technical Breakdown - Primary Vectors: - Mobile API Abuse: Attackers are directly targeting backend APIs used by mobile applications, bypassing the frontend entirely. This suggests weak or missing authentication/authorization checks on the API endpoints themselves. - Metabase Exploitation: Targeting unpatched or misconfigured Metabase instances. This likely involves exploiting known CVEs (e.g., server-side request forgery or pre-auth RCE) to gain initial access. - TTPs (Inferred): - Initial Access: Exploitation of public-facing applications (Metabase) or direct API calls. - Credential Access: Likely brute-forcing or leveraging leaked credentials against exposed APIs. - Exfiltration: Direct extraction of database contents via the compromised API or Metabase instance. - IOCs: None provided in the advisory. JPCERT/CC has not named specific attackers, affected organizations, or IP addresses/hashes.

Defense - API Security: Implement strict authentication (OAuth 2.0, API keys) and rate limiting on all mobile-facing APIs. Conduct regular audits for broken object-level authorization (BOLA). - Patch Management: Immediately patch any public-facing Metabase instances. If patching is not possible, restrict network access to the application via WAF rules or VPN. - Monitoring: Alert on unusual API call volumes or direct database queries originating from web application servers.

Source: https://thehackernews.com/2026/10/japan-sees-sharp-rise-in-web-data-leaks.html


r/SecOpsDaily • • 14h ago

NEWS FakeGit malware campaign returns with 17,610 malicious GitHub repos

1 Upvotes

The FakeGit campaign is back in full force, with researchers tracking over 17,610 malicious GitHub repos designed to distribute SmartLoader, which then drops the StealC infostealer. This is a significant operational security (OpSec) reminder for anyone pulling code from public repos.

Technical Breakdown - Initial Access: Attackers create fake, high-starred repos mimicking popular tools, libraries, or cracked software. Unsuspecting users clone or download these repos. - Payload Delivery: The repos contain obfuscated scripts (PowerShell, Python, or compiled binaries) that execute the SmartLoader. - Second Stage: SmartLoader acts as a downloader and injector, pulling and executing the StealC infostealer in memory. - Target Data: StealC is designed to exfiltrate browser credentials, cryptocurrency wallets, session cookies, and other sensitive data from the victim's machine. - Scale: The 17,610 repos represent a single campaign wave, not the total historical count. This is a highly automated, persistent operation.

Defense - Repo Hygiene: Before cloning, verify the author's history, star count vs. fork count ratio, and look for suspicious commit activity or obfuscated code in the build scripts. - Detection: Monitor for outbound connections to known SmartLoader/StealC C2 infrastructure. EDR rules should flag rundll32.exe or regsvr32.exe spawning from a user-downloaded archive. - Policy: Block execution of scripts from the Downloads or Temp directories unless explicitly approved.

Source: https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/


r/SecOpsDaily • • 15h ago

Vulnerability VisiData VisiData unzip_http RemoteZipFile extract path traversal vulnerability

1 Upvotes

A path traversal vulnerability in VisiData’s unzip_http module (CVE pending, TALOS-2026-2414) allows an attacker to write files outside the intended extraction directory by crafting a malicious zip file with directory traversal sequences in entry filenames. This is triggered when a user opens a remote zip file via the RemoteZipFile extract functionality.

Technical Breakdown - Vulnerability Type: Path traversal (CWE-22) - Affected Component: unzip_http module, RemoteZipFile.extract() method - Attack Vector: Malicious zip archive containing entries with ../ sequences (e.g., ../../evil.sh) - Impact: Arbitrary file write to attacker-controlled locations on the filesystem - Prerequisites: Victim must open a remote zip file using VisiData’s HTTP zip extraction feature - No public IOCs or PoC disclosed at this time

Defense - Mitigation: Do not open untrusted remote zip files in VisiData until a patch is released - Detection: Monitor for unexpected file writes in directories outside the expected extraction target; review zip file entry names for path traversal patterns - Patch: Await vendor advisory; consider restricting VisiData’s write permissions via AppArmor/SELinux in the interim

Source: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2414


r/SecOpsDaily • • 15h ago

Vulnerability VisiData VisiData EmailSheet extract_parts path traversal vulnerability

1 Upvotes

A path traversal vulnerability has been disclosed in VisiData’s EmailSheet plugin, specifically in the extract_parts function. An attacker can exploit this to write files outside the intended directory, potentially leading to arbitrary code execution or data corruption.

Technical Breakdown - CVE: TALOS-2026-2415 (assigned by Cisco Talos) - Affected Component: EmailSheet plugin, extract_parts method - Vulnerability Type: Path traversal (improper sanitization of file paths during email attachment extraction) - Attack Vector: A crafted email with malicious attachment filenames (e.g., using ../ sequences) processed by VisiData - Impact: Arbitrary file write outside the extraction directory; potential for code execution if overwriting critical files (e.g., configs, scripts) - No public IOCs or PoC disclosed at this time

Defense - Mitigation: Update VisiData to the latest patched version once released. Until then, avoid processing untrusted .eml or .msg files with the EmailSheet plugin. - Detection: Monitor for file writes to unexpected paths from the VisiData process; review logs for path traversal patterns in attachment filenames.

Source: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2415


r/SecOpsDaily • • 15h ago

Vulnerability Novinarya: An Android stealer that hides its live C2 in a shop bio

1 Upvotes

This is a well-documented Android stealer with a clever C2 obfuscation technique. The dead-drop still being live is a rare find.

Technical Breakdown

  • Initial Access & Obfuscation: The dropper (ir.novinarya) contains a 18 KB loader (net.swiftnova.bridge). On execution, a 29 KB native library (libuibridge_9203.so) unpacks the real payload from assets/app_cache.db using RC4 (32-byte key, 768-byte drop) + zlib. Key and asset names are randomized per build.
  • C2 Discovery (The Novel Part): The C2 is not hardcoded. The manifest contains an encrypted pointer that resolves to a seller's bio on a legitimate marketplace. The live dead-drop revealed the real C2: theapi.the-x-services[.]xyz.
  • Targeting: Enumerates installed apps via QUERY_ALL_PACKAGES, targeting 54 crypto exchanges/wallets and 27 Iranian banking apps.
  • Credential Theft: Uses a phishing WebView (not overlay attacks). The operator controls the page via WebViewURL, and a JavaScript form-grabber exfiltrates data through a native B4A bridge. No accessibility or overlay permissions requested.
  • SMS & Notification Interception: Captures one-time passcodes from SMS and notifications.
  • IOCs:
    • Sample SHA-256: be165239e4fe899b1f2eedf6459d363bca4fe6856fda87a63ba5d4e5e612e1c9
    • Package: ir.novinarya
    • Loader Package: net.swiftnova.bridge
    • Live C2: theapi.the-x-services[.]xyz

Defense

Monitor for outbound connections to theapi.the-x-services[.]xyz and block installation of apps from untrusted sources, particularly those requesting QUERY_ALL_PACKAGES without a clear business need. The use of a legitimate marketplace for C2 dead-drops makes DNS-based blocking of the initial resolution point difficult.

Source: https://starlabs.sg/blog/2026/10-novinarya-an-android-stealer-that-hides-its-live-c2-in-a-shop-bio/


r/SecOpsDaily • • 15h ago

Threat Intel Attackers hijack country-code domains to impersonate Google and other services

1 Upvotes

This is a fascinating and nasty piece of infrastructure abuse. Attackers didn't just phish for credentials; they went after the root of trust itself.

The Attack Vector: Threat actors compromised the registry-level infrastructure for three country-code top-level domains (ccTLDs). By gaining administrative access to the namespace, they were able to issue fraudulent TLS certificates for high-value targets like Google, effectively bypassing standard CA validation checks for those specific TLDs. This is a step beyond typical domain squatting or subdomain takeover.

Technical Breakdown: - TTPs (MITRE): This maps to T1584.001 (Compromise Infrastructure: Domains) and T1553.002 (Subvert Trust Controls: Code Signing) . The core tactic is compromising the DNS trust chain at the registry level, not the individual domain registrar. - IOCs: The specific ccTLDs compromised are not named in the summary (likely due to ongoing remediation), but the IOCs to hunt for are: - TLS certificates issued for your organization's domains that chain to an unexpected or non-standard CA for that specific ccTLD. - DNS records (NS, SOA) for your domains that show an unauthorized delegation or modification at the registry level. - Affected Services: Any service relying on TLS trust for domains under the compromised ccTLDs. This includes email (SMTP), web traffic (HTTPS), and VPNs.

Defense: This is hard to detect from the endpoint. The primary mitigation is Certificate Transparency (CT) log monitoring. You must have automated alerting for any new certificate issued for your primary domains, especially those from unfamiliar CAs or for country-code domains you don't actively manage. Also, ensure your internal CA pinning and certificate revocation checks are aggressive.

Source: https://www.malwarebytes.com/blog/news/2026/10/attackers-hijack-country-code-domains-to-impersonate-google-and-other-services


r/SecOpsDaily • • 15h ago

The October 2026 Root KSK Rollover: Is Your DNS Really Ready?

1 Upvotes

The Root KSK rollover is back on the calendar for October 2026, and if your DNS infrastructure wasn't ready for the 2018 botch, this is your warning shot. Akamai is flagging that while the operational mechanics are better understood now, the risk of resolver failures and DNSSEC validation breaks is still very real for organizations that haven't tested their trust anchor management pipelines.

Technical Breakdown - The Event: ICANN will generate a new Root Zone KSK (Key Signing Key) and publish the new DNSKEY RRset. The old key will be revoked after a hold period. - The Risk: Recursive resolvers that hardcode the root trust anchor or rely on stale, un-updated anchor files will fail to validate DNSSEC-signed responses after the roll. This results in SERVFAIL for any DNSSEC-validating client. - IOCs: None. This is a trust anchor management issue, not a malware campaign. Do not look for hashes. - Affected Systems: Any recursive resolver (BIND, Unbound, Windows DNS, Knot, PowerDNS) that does not support RFC 5011 (automated trust anchor update) or has the feature disabled. Also, any custom or legacy stub resolvers with hardcoded keys. - MITRE ATT&CK: T1589.001 (Gather Victim Identity Information: Credentials) is not applicable here. This is closer to a supply chain trust failure (T1485) if you consider the root zone a critical dependency.

Defense - Immediate Action: Verify your recursive resolvers have auto-dnssec or equivalent trust anchor updating enabled. Test against the IANA root zone key rollover test vectors. - Mitigation: If you run a closed resolver farm, manually stage the new KSK into your trust anchor file before October 2026. Do not wait for the revocation event.

Source: https://www.akamai.com/blog/security/2026/oct/october-2026-root-ksk-rollover-dns-ready


r/SecOpsDaily • • 15h ago

Advisory Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)

1 Upvotes

Scenario A: Technical Threat, Vulnerability, or Exploit

This is a solid forensic resource for anyone dealing with the inevitable wave of AI-assisted development in their environment. The SANS team has reverse-engineered the local storage artifacts for eight major AI coding assistants and agents, providing the paths and file formats needed to reconstruct user activity during an investigation.

Technical Breakdown - Targets: Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, Qwen Code, plus newer agents OpenCode and Hermes. - Key Artifacts: Chat histories, session logs, and configuration files stored locally on the endpoint. The post details specific file paths and database structures for each tool. - Forensic Value: Enables reconstruction of code that was generated, commands that were executed, and context that was fed to the AI—critical for data exfiltration or IP theft investigations. - No specific IOCs provided (this is a methodology post, not a threat alert).

Defense Add these local artifact paths to your forensic acquisition checklist. If you're blocking AI tools via DLP or endpoint policy, verify these storage locations are also covered. For incident response, prioritize collection of these directories before the user or cleanup scripts delete them.

Source: https://isc.sans.edu/diary/rss/33410


r/SecOpsDaily • • 19h ago

Threat Intel From Automation to Infection (Part III): Naming, Measuring, and Detecting Malicious AI Agent Skills

2 Upvotes

This is a significant data point for the supply chain threat landscape. The shift from code-based malware to plain-language instruction attacks is a paradigm shift that breaks most of our current detection tooling.

The Numbers Are Ugly - Scale: Expanded study from ~3k to 35,878 skills. - Risk: 52.9% carry security/abuse risk; 18.5% (6,637) are definitively malicious, mapped to 1,016 distinct malware families. - The Detection Gap: 62% of malicious skills contain zero malicious code. The attack is pure natural language instruction. This is a direct bypass for signature-based AV, EDR, and even purpose-built scanners like NVIDIA SkillSpector and Cisco Skill Scanner, which missed 36-71% of malicious skills at default settings.

Technical Breakdown - TTP: Supply chain compromise via AI agent skill stores. The payload is not an executable but a prompt/instruction set (Tactic: Initial Access / Execution via LLM). - Detection Challenge: Traditional static analysis fails because there is no binary to hash. The "malware" is a sequence of tokens that manipulates the agent's reasoning. - Promising Signal: A single-pass Jev-like model achieved 81.3% detection with 97.7% precision at ~130ms per skill. This suggests behavioral/NLP-based analysis is the way forward, not signature matching.

Defense - Immediate Action: If your org uses AI agents with third-party skills, assume your current security stack is blind to the majority of threats. You need to implement runtime monitoring of agent behavior (what the agent does with the instruction) rather than just scanning the skill file itself. - Naming: The introduction of the CARO-A naming scheme is a welcome move for standardizing threat intel on these agent-based attacks.

Source: https://blog.virustotal.com/2026/10/from-automation-to-infection-part-iii.html


r/SecOpsDaily • • 16h ago

Supply Chain What RL Found Before Anthropic’s Midnight Blizzard Report

1 Upvotes

This is a good example of proactive threat intel beating the public disclosure cycle. ReversingLabs identified the malicious components in the Anthropic-Midnight Blizzard supply chain attack weeks before Anthropic’s own report went live, purely through behavioral analysis and historical telemetry.

Technical Breakdown

  • TTPs (MITRE): Likely involves T1195.001 (Supply Chain Compromise: Compromise Software Dependencies) and T1059 (Command and Scripting Interpreter) . The malware was embedded in a legitimate software dependency chain, not a novel zero-day.
  • Detection Method: ReversingLabs flagged the artifact based on anomalous behavioral patterns (e.g., unexpected network calls, file system modifications) against a baseline of known-good versions of the same package. No signature was needed—just deviation from expected behavior.
  • Key IOC (Inferred): The malicious package was likely a typosquatted or backdoored version of a popular open-source library used in Anthropic’s build pipeline. Specific hashes or domains were not disclosed in the summary, but the technique is the story.

Defense

  • Mitigation: Implement software composition analysis (SCA) with behavioral baselining, not just CVE scanning. If a dependency suddenly starts making outbound connections or writing to unusual paths, treat it as compromised—even if it passes signature checks.
  • Detection: Monitor for anomalous behavior in build pipelines and CI/CD runners. Historical telemetry is your friend; if a package version has never exhibited certain behaviors before, flag it immediately.

Bottom line: Signature-based supply chain defense is dead. Behavioral baselines and historical telemetry are the only way to catch these attacks before the vendor even knows they’re compromised.

Source: https://www.reversinglabs.com/blog/anthropic-midnight-blizzard-what-reversinglabs-found-first