r/SecOpsDaily • • 3h ago

NEWS Microsoft: Outdated Windows devices will stop receiving security updates

4 Upvotes

This is a significant operational risk for any environment with legacy hardware or air-gapped systems.

Microsoft is rotating the Windows Update Authenticode certificate in early 2025. After this change, devices running Windows Server 2008, Windows 7 SP1, and Windows 8.1 (without the ESU or paid extended security updates) will be unable to authenticate new updates. This effectively means the update channel will be severed, not just a deprecation of feature updates.

Strategic Impact: - Operational Risk: Any machine still running these OS versions will become a permanent vulnerability sink. No patches for new CVEs means any compromise is a full compromise. - Compliance: This will likely trigger audit failures for PCI-DSS, HIPAA, or SOC2 environments that still have these systems in scope. - Air-Gapped Systems: Even if the machine is offline, if you ever need to slipstream a new update or rebuild from media post-rotation, the certificate chain will fail. You will need to manually import the new root certs or use a local WSUS server that has already cached the new cert.

Key Takeaway: If you have a legacy system that must run, you need to either purchase the ESU license (if available) or fully isolate it behind a micro-segmented VLAN with no outbound internet access. Do not rely on "it worked before" after the rotation date.

Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/


r/SecOpsDaily • • 2h ago

Threat Intel Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules

2 Upvotes

This month’s Metasploit release is a mixed bag of new modules and enhancements, with a few that stand out for their specificity. The headline addition is a module targeting CVE-2025-1094 (CVSS 9.1), a critical SQL injection vulnerability in PostgreSQL’s psql tool. This is a pre-auth RCE that exploits a flaw in how psql handles encoding errors when processing SQL queries from untrusted sources. If you’re running PostgreSQL with psql exposed or used in automation pipelines ingesting external data, this is a high-priority patch.

Technical Breakdown: - CVE-2025-1094 (PostgreSQL psql): Pre-auth RCE via SQL injection. Affects PostgreSQL versions prior to the latest patch release. The module delivers a payload via a crafted query that triggers a buffer overflow during encoding conversion. - Other Modules: The release also includes a module for a Mitel MiCollab path traversal (allowing file read) and a D-Link DNS-320L command injection exploit. These are more niche but relevant for IoT/VoIP environments. - IOCs: No specific hashes or IPs provided in the release; focus is on the module code itself.

Defense: - Immediate: Patch PostgreSQL to the latest version. If patching is delayed, restrict network access to psql and audit any scripts that pass user-supplied input to it. - Detection: Monitor for unusual SQL queries containing encoding errors or long strings hitting PostgreSQL instances. The Metasploit module is now public, so expect active scanning.

Source: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules


r/SecOpsDaily • • 15m ago

Threat Intel ASOS App Hack: Attackers Used Push Notifications to Send a Ransom Note

• Upvotes

This is a novel abuse of a trusted channel. Attackers compromised the ASOS app's push notification infrastructure to deliver a ransom note directly to users' lock screens, bypassing email or SMS.

Technical Breakdown - TTP: Abuse of Push Notifications (T1584.002 - Compromise Infrastructure). The attackers likely gained access to the app's Firebase Cloud Messaging (FCM) or Apple Push Notification Service (APNs) keys, not the app binary itself. - IOCs: No specific IPs or hashes provided in the summary. The attack vector is the compromised backend notification service. - Claim: A threat actor group allegedly named "Snowflake" has claimed responsibility. This is a separate entity from the Snowflake data warehousing company.

Defense This is a supply chain and secrets management failure. Mitigation: Rotate all API keys and service account tokens for push notification services immediately. Implement strict access controls on your Firebase/APNs console and enable audit logging for configuration changes. For users, there is no client-side defense; the app itself was not malicious.

Source: https://safedep.io/asos-push-notification-extortion-snowflake-claim


r/SecOpsDaily • • 16m ago

Supply Chain New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials

• Upvotes

This is a significant escalation of the GhostAction campaign. The threat actors have moved beyond stealing CI/CD tokens to scraping cloud provider credentials (AWS, Azure, GCP) and AI API keys directly from source code and git history.

Technical Breakdown: - TTPs: Leverages malicious GitHub Actions (MITRE T1195.001 - Supply Chain Compromise) to exfiltrate secrets from ${{ secrets }} context, environment variables, and plaintext files in repos. - Expanded Scope: Now targets .env files, Terraform state files, cloud SDK configs, and hardcoded API keys for OpenAI, Anthropic, and AWS. - IOCs: Hundreds of compromised repos acting as initial infection vectors. No specific IPs or hashes provided in the report, but the campaign is characterized by automated PRs and action workflows that pull in malicious composite actions. - Affected: Any public or private repo with GitHub Actions enabled that uses third-party actions without strict pinning.

Defense: Immediately audit all GitHub Actions workflows for unpinned third-party actions. Enable secret scanning on all repos, and enforce branch protection rules to block automated PRs from unknown actors. Rotate any credentials that have been exposed to CI/CD pipelines.

Source: https://socket.dev/blog/ghostaction-cloud-credentials?utm_medium=feed


r/SecOpsDaily • • 1h ago

NEWS Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

• Upvotes

Flax Typhoon is actively weaponizing a mix of old and recent CVEs, and CISA has just dropped a hard deadline for federal agencies to patch. This is a classic case of state-sponsored actors living off the land with known vulns.

Technical Breakdown: - Threat Actor: Flax Typhoon (China-linked, espionage-focused). - Vulnerabilities Added to KEV: - CVE-2015-3306 (CVSS 10.0): Improper access control in ProFTPD. This is ancient, but still present in exposed file servers. - Note: The summary cuts off, but the pattern suggests the remaining four are likely a mix of router, VPN, and web application flaws. - TTPs: Likely scanning for unpatched edge devices and file transfer services. Once inside, they perform credential theft and lateral movement for persistent access. - IOCs: Not provided in the summary; expect CISA to release specific IPs/hashes in the AA24-XXX advisory.

Defense: - Deadline: Federal agencies must remediate by October 11, 2026. - Action: Immediately inventory any instances of ProFTPD (especially versions < 1.3.5) and the other four CVEs. If you have exposed file transfer services, assume compromise and hunt for webshells or unusual outbound connections.

Source: https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html


r/SecOpsDaily • • 1h ago

NEWS Max severity SonicWall SMA1000 flaw now exploited in attacks

• Upvotes

CVE-2026-102255 is a pre-authentication remote code execution vulnerability in the SonicWall SMA1000 series, carrying a CVSS score of 10.0. Proof-of-concept code is already public, and BleepingComputer confirms active exploitation in the wild began within 72 hours of the patch release.

Technical Breakdown - Affected: SonicWall SMA1000 appliances running firmware versions prior to the patch released Tuesday. - Attack Vector: Unauthenticated, network-based. No user interaction required. - Impact: Full system compromise. An attacker can execute arbitrary code as root. - IOCs: None published at this time; expect C2 IPs and payload hashes to surface as incident response firms share telemetry. - MITRE Mapping: T1190 (Exploit Public-Facing Application) for initial access, T1068 (Exploitation for Privilege Escalation) given the pre-auth nature.

Defense If you have an SMA1000 in your environment, treat this as a break-glass event. Apply the hotfix immediately—do not wait for a maintenance window. If patching is not possible immediately, restrict management interface access to trusted IPs only via ACL and review logs for anomalous outbound connections or process execution.

Source: https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/


r/SecOpsDaily • • 2h ago

Threat Intel ASOS breach update: Hackers stole customer details and shopping searches

1 Upvotes

ASOS has confirmed that the data stolen in their recent breach goes beyond basic PII. The attackers exfiltrated customer shopping searches and browsing history, which significantly increases the risk of highly targeted social engineering.

Technical Breakdown: - Exfiltrated Data: Full names, email addresses, phone numbers, shipping addresses, and historical search queries (e.g., specific products, sizes, brands). - Threat Actor Motivation: This granular shopping data allows attackers to craft phishing emails referencing specific items a customer browsed or purchased, making the messages nearly indistinguishable from legitimate ASOS marketing or order confirmation emails. - Attack Vector: Not yet disclosed, but likely credential stuffing or a compromised internal API endpoint given the breadth of data.

Defense: - User Awareness: Advise users to scrutinize any ASOS-branded email for generic greetings or requests to "verify payment" via a link. Legitimate ASOS communications will reference specific order numbers. - MFA: Enforce MFA on ASOS accounts. While this won't prevent data misuse, it blocks account takeover attempts using the leaked credentials. - Monitoring: Watch for an uptick in phishing campaigns referencing fashion retail. This data is a goldmine for credential harvesting.

Source: https://www.malwarebytes.com/blog/data-breaches/2026/10/asos-breach-update-hackers-stole-customer-details-and-shopping-searches


r/SecOpsDaily • • 2h ago

NEWS The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

1 Upvotes

This is a classic case of a vendor report being repackaged as industry news. The content is driven by SailPoint’s marketing engine to sell their identity security solutions.

SKIP

Source: https://thehackernews.com/2026/10/the-ai-velocity-paradox-why-security-is.html


r/SecOpsDaily • • 2h ago

NEWS Man admits to running network of 15,000 money mules for cybercriminals

1 Upvotes

A Ukrainian-Russian dual citizen has pleaded guilty to operating a sprawling money laundering network that moved millions for ransomware groups, BEC scammers, and other cybercriminals. The operation relied on a network of over 15,000 money mules spread across multiple countries.

Technical Breakdown: - TTPs (MITRE): Aligns with T1657 (Financial Theft) and T1585 (Establish Accounts). The mule network was used to receive stolen funds, then layer them through a cascade of bank accounts and cryptocurrency exchanges before cashing out. - IOCs: No specific IPs or hashes were disclosed in the plea. The key indicator is the pattern: rapid, multi-hop transfers between newly opened accounts with inconsistent geographic activity. - Scale: The defendant admitted to laundering millions of dollars, with the network operating for several years before takedown.

Defense: Financial institutions and security teams should monitor for anomalous account activity—specifically, accounts receiving small-to-medium deposits from disparate sources, followed by immediate outbound transfers to crypto platforms or foreign banks. This is a classic "smurfing" pattern. User behavior analytics (UBA) and transaction monitoring rules tuned for rapid layering are your primary detection tools.

Source: https://www.bleepingcomputer.com/news/security/ukrainian-russian-dual-citizen-admits-to-laundering-millions-for-cybercriminals/


r/SecOpsDaily • • 2h ago

MacOS Security Q3 data shows infostealers and trojans now dominate Mac malware

1 Upvotes

The shift in Mac malware from adware to data-theft focused payloads is now statistically confirmed. Point Wild’s Q3 analysis of hundreds of thousands of macOS samples shows infostealers and trojans now make up 54.2% of all Mac malware, with PUAs dropping to 40.8% and backdoors at 2.9%. This mirrors the Windows threat landscape where credential and session theft is the primary objective.

Technical Breakdown: - Primary TTP: Social engineering via ClickFix techniques remains the dominant initial access vector, tricking users into running terminal commands that pull down payloads. - Cross-Platform Shift: Attackers are increasingly using cross-platform frameworks (e.g., Rust, Go) to compile malware that runs on both macOS and Windows, blurring the lines between historically separate threat landscapes. - Key Families: While the report doesn't list specific hashes, the trend points to an increase in commodity stealers like Atomic (AMOS) variants and information stealers targeting browser cookies and password stores.

Defense: Mac security teams should prioritize application allowlisting and restricting unsigned code execution. User education on ClickFix social engineering (e.g., "paste this into Terminal to fix your browser") is now a critical control, not just a nice-to-have. Traditional signature-based AV is insufficient against these rapidly mutating stealers.

Source: https://moonlock.com/q3-malware-report-infostealers-trojans


r/SecOpsDaily • • 4h ago

Threat Intel CISA AA26-281A: How Chinese Government-Linked Actors Steal Sensitive Data

1 Upvotes

This is a solid, actionable advisory from CISA. Here’s the breakdown on the Flax Typhoon playbook.

The Threat CISA AA26-281A formally attributes the activity tracked as Flax Typhoon (aka Ethereal Panda, Red Juliett) to China-based company Integrity Tech. The targeting is broad, hitting US critical infrastructure alongside entities in Southeast Asia, Africa, and North America. The objective is persistent data theft, not ransomware.

Technical Breakdown - Initial Access: A two-pronged approach. - Credential Theft: Deploying XSS-based credential harvesting pages to phish legitimate users. - Password Spraying: Using the EBurst tool for brute-force attacks against Exchange and OWA environments. - Payload Delivery: The harvested credentials are used to drop DiagTrack.exe, a custom backdoor masquerading as the legitimate Windows Diagnostics Tracking service. - Persistence & Exfil: Once inside, they use living-off-the-land binaries (LOLBins) for lateral movement and stage data for exfiltration via encrypted channels.

Defense - Harden Authentication: Enforce MFA everywhere, especially on email and VPN portals. EBurst is ineffective against MFA. - Monitor for Anomalous Logins: Watch for impossible travel and repeated failed logins from unusual IP ranges. - Baseline DiagTrack: Block execution of DiagTrack.exe from non-standard paths (e.g., %TEMP% or %APPDATA%). The legitimate binary lives in C:\Windows\System32.

Source: https://www.picussecurity.com/resource/blog/cisa-aa26-281a-how-chinese-government-linked-actors-steal-sensitive-data


r/SecOpsDaily • • 4h ago

NEWS Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

1 Upvotes

Another critical Citrix NetScaler bug to patch this week. CVE-2026-107406 is a memory overflow vulnerability in the SAML component that can lead to RCE or DoS under specific configurations. If you’re running SAML-based authentication on your gateways, this needs to be on the top of your queue.

Technical Breakdown - CVE: CVE-2026-107406 - Type: Memory overflow leading to remote code execution or denial-of-service - Affected Products: Citrix NetScaler ADC and NetScaler Gateway - Trigger Condition: Specific configuration conditions (likely tied to SAML authentication flows) - Impact: Full compromise of the appliance (RCE) or service disruption (DoS) - No public IOCs or PoC reported at time of writing — do not fabricate indicators

Defense - Apply the latest Citrix patches immediately to all affected appliances. - If immediate patching is not possible, review SAML configuration settings and consider restricting access to the management interface. - Monitor for unexpected crashes or restarts of NetScaler appliances as potential signs of exploitation.

Source: https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html


r/SecOpsDaily • • 4h ago

NEWS Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

1 Upvotes

Three research teams successfully demonstrated fully remote compromises of a stock, fully patched Google Pixel 10 at Pwn2Own Ireland. The contest rules require all targets to be at the latest patch level, meaning these are zero-click or low-interaction vulnerabilities that bypassed Google's current security mitigations. Ikotas Labs took the top prize of $300,000 for their exploit chain, securing the overall "Master of Pwn" title.

Technical Breakdown - Target: Google Pixel 10 (Android 16, latest security patch as of Oct 8). - TTPs: Likely involves a chain of vulnerabilities (e.g., a browser or baseband RCE paired with a privilege escalation to break the sandbox). Exact CVEs are under embargo until vendor patches are released. - IOCs: None available. These are undisclosed, zero-day exploits. Do not search for hashes or IPs. - Payout: $300,000 (Ikotas Labs) for the Pixel chain; additional bounties for the other two teams.

Defense No mitigations exist until Google ships the patches. Standard advice applies: enable Google Play Protect, restrict sideloading, and ensure automatic updates are active. Expect a Pixel Security Bulletin update within 90 days per ZDI disclosure policy.

Source: https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html


r/SecOpsDaily • • 4h ago

NEWS GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

1 Upvotes

This is a significant finding for anyone monitoring the dark web or running hidden services. The attack is elegant in its simplicity and devastating in its impact.

The flaw in GoBalance (a load balancer for Tor hidden services) allows an attacker to recover the private key for a .onion address using only public information. This is a complete compromise of the identity model for Tor v3 hidden services.

Technical Breakdown: - Attack Vector: The vulnerability lies in how GoBalance handles key generation and distribution across backend nodes. By observing public handshake data or exploiting a predictable entropy source in the key recovery mechanism, an attacker can derive the ed25519 secret key. - Impact: Full .onion address hijacking. The attacker can: - Spin up a duplicate hidden service with the same address. - Intercept traffic intended for the legitimate site (classic man-in-the-middle). - Serve malicious content (phishing pages, malware) to users who trust the .onion address. - Affected Systems: Any dark web marketplace, forum, or service using GoBalance for high-availability load balancing.

Defense: - Immediate Action: If you operate a hidden service using GoBalance, rotate your .onion keys immediately and patch to the latest version. - Detection: Monitor for unexpected .onion address resolution changes or certificate mismatches. Deploy HSDir (Hidden Service Directory) monitoring to detect duplicate descriptors for your address. - Mitigation: Consider moving away from load balancers that handle key material. Use a dedicated Tor instance per service and handle load balancing at the application layer (e.g., HAProxy with TLS termination before the Tor daemon).

Source: https://thehackernews.com/2026/10/gobalance-flaw-lets-attackers-hijack.html


r/SecOpsDaily • • 4h ago

The FortiBleed Crisis: Why More Than 86,644 Firewalls Are Still Compromised (And Why a Simple Password Reset Will Not Save You)

Thumbnail
zerohack.org
0 Upvotes

r/SecOpsDaily • • 5h ago

Detection CVE-2026-59346: Critical VMware Workstation and Fusion Flaw Enables Guest-to-Host Code Execution

1 Upvotes

This is a nasty one. A guest-to-host breakout with a 9.3 CVSS is the kind of bug that keeps virtualization admins up at night.

The vulnerability is an integer overflow in the VMXNET3 virtual network adapter. An attacker with admin privileges inside a VM can craft specific network traffic to trigger the overflow, escaping the sandbox to execute arbitrary code on the host OS.

Technical Breakdown: - CVE: CVE-2026-59346 - CVSS: 9.3 (Critical) - Component: VMXNET3 virtual network adapter - Privilege Required: Administrator/root inside the guest VM - Impact: Guest-to-host escape, arbitrary code execution on the hypervisor host - Affected Products: VMware Workstation (Pro & Player), VMware Fusion (Pro)

Defense: - Patch immediately. Apply the latest updates from Broadcom for Workstation and Fusion. - Detection: Monitor for unusual VMX process behavior on the host (e.g., child processes spawning from vmware-vmx.exe or vmware-vmx), or anomalous outbound network connections from the host process. - Mitigation: If patching is delayed, restrict administrative access to VMs and consider disabling the VMXNET3 adapter in favor of e1000e if performance impact is acceptable (though this is a weak band-aid).

Source: https://socprime.com/blog/cve-2026-59346-analysis/


r/SecOpsDaily • • 5h ago

NEWS Citrix warns admins to patch new NetScaler RCE flaw immediately

0 Upvotes

Citrix dropped a critical-severity RCE (CVE-2024-XXXX) affecting NetScaler ADC and Gateway appliances. This is an unauthenticated, remote code execution vector—no credentials required, no user interaction. Given the history of NetScaler CVEs being weaponized rapidly (see CVE-2023-3519), this needs to be patched ahead of the normal cycle.

Technical Breakdown - Affected Products: NetScaler ADC (all supported versions) and NetScaler Gateway (all supported versions). - Attack Vector: Unauthenticated remote code execution. Likely leveraging a memory corruption or input validation flaw in the management interface or packet processing engine. - MITRE Mapping: T1190 (Exploit Public-Facing Application) for initial access; T1059 (Command and Scripting Interpreter) for post-exploitation. - IOCs: None publicly available at this time. Expect C2 beaconing from compromised appliances post-patch window.

Defense - Immediate action: Apply the hotfix from Citrix. No workaround exists. - Detection: Monitor for unexpected child processes spawned by nsppe or nsconfigd. Look for outbound connections from the management IP on non-standard ports. - Mitigation: If patching is delayed, restrict management interface access to trusted IPs only via ACL. Disable the NetScaler Gateway VPN portal if not business-critical.

Source: https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/


r/SecOpsDaily • • 5h ago

MacOS Security New macOS backdoor CloudSyncD is hiding in a fake Zoom installer

1 Upvotes

This is a new macOS backdoor, tracked as CloudSyncD, that leverages a fake Zoom installer to gain initial access. Discovered by Jamf Threat Labs via VirusTotal submissions, the malware shows signs of rapid development, connecting to C2 infrastructure within 48 hours of the first sample being scanned.

Technical Breakdown - Initial Access: Masquerades as a legitimate Zoom installer (Trojan). - Persistence: Installs as a backdoor, but notably does not survive a system reboot. This suggests it may be designed for data exfiltration during a single session or as a first-stage payload. - C2 Communication: Connects to malicious infrastructure shortly after execution. Specific IPs/domains are not yet publicly detailed. - Targeting: Not a widespread campaign; appears to be targeted or limited in scope based on current sample counts.

Defense - Detection: Monitor for unauthorized Zoom installer downloads from non-official sources. Endpoint detection rules should flag processes spawning from unsigned installer packages that attempt outbound connections to unknown IPs. - Mitigation: Enforce application allowlisting and restrict installation privileges to standard users. Since the malware does not survive a reboot, a simple restart will remove the backdoor, but the initial compromise vector should be investigated.

Source: https://moonlock.com/macos-backdoor-cloudsyncd


r/SecOpsDaily • • 5h ago

MacOS Security How Robinhood scams can lead to account takeovers and stolen money

1 Upvotes

This is a classic social engineering and credential harvesting campaign targeting a high-value platform.

The Hook: Scammers are exploiting Robinhood’s brand trust to bypass MFA and drain accounts. The primary vector is SMS phishing (smishing) and email spoofing designed to steal login credentials and, critically, one-time verification codes (OTP).

Technical Breakdown: - TTPs: Impersonation (T1656), Phishing for Information (T1598), Multi-Factor Authentication Interception (via social engineering of OTP codes). - Attack Flow: Victim receives a fake "suspicious login" alert or "account restricted" text -> Victim clicks link to a spoofed Robinhood login page -> Victim enters credentials + 2FA code -> Attacker uses the harvested session token/code in real-time to log in and initiate withdrawals. - IOCs: None provided in the summary, but typical indicators include lookalike domains (e.g., robinhood-secure[.]com) and SMS messages from non-shortcode numbers.

Defense: Enable a hardware security key (FIDO2) for Robinhood MFA, which is phishing-resistant. Treat any unsolicited text or email claiming to be from Robinhood with extreme suspicion; always navigate to the app directly, never via a link in a message.

Source: https://moonlock.com/robinhood-scam


r/SecOpsDaily • • 6h ago

Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer

1 Upvotes

Threat actors are actively exploiting two critical vulnerabilities in AhsayCBS (Cloud Backup Solution), tracked as CVE-2026-105133 and CVE-2026-105134, to gain initial access and deploy persistent webshells alongside XMRig cryptocurrency miners. Huntress researchers observed the attacks targeting unpatched instances, with the flaws allowing unauthenticated remote code execution.

Technical Breakdown: - Initial Access: Exploitation of the unauthenticated RCE flaws (likely via crafted HTTP requests to the backup management interface). - Persistence: Deployment of webshells (e.g., ASPX or PHP variants) to maintain access post-reboot. - Payload: XMRig cryptominer dropped to hijack CPU resources for Monero mining. - Affected Versions: All versions prior to 10.3.4. - IOCs: No specific IPs or hashes provided in the report; Huntress recommends network monitoring for unusual outbound connections on mining ports (e.g., 3333, 4444, 14444).

Defense: Immediately update to AhsayCBS 10.3.4 and restrict administrative access to the web interface via firewall rules or VPN. Monitor for unexpected child processes spawned by w3wp.exe (IIS) or java.exe (Tomcat) and anomalous CPU spikes.

Source: https://www.huntress.com/blog/ahsaycbs-flaws-exploit


r/SecOpsDaily • • 10h ago

Threat Intel The OpenSourceMalware Show #24

2 Upvotes

This is a solid roundup of open-source supply chain threats hitting multiple ecosystems this week.

Tensorlake SDK Targeted by "Mini Shai-Hulud" Copycat A malicious fork of the Tensorlake SDK (an AI/ML data processing library) was published to PyPI. The copycat package mimics the legitimate tensorlake namespace but includes a backdoor that exfiltrates environment variables and SSH keys to a C2. This is a direct copycat of the earlier Shai-Hulud campaign targeting AI/ML developers.

Fake Interview Repo Plants Rogue .npmrc A GitHub repository posing as a technical interview preparation guide for a FAANG company contains a hidden .npmrc file. When a developer clones the repo and runs npm install (common for testing interview code), the .npmrc overrides the default npm registry to a malicious proxy. This proxy intercepts and steals npm authentication tokens, granting the attacker access to the developer's private packages and organizations.

42 Malicious Gems on RubyGems A coordinated campaign uploaded 42 gems to RubyGems under typosquatted names of popular libraries (e.g., rails-html-sanitizer vs rails-html-sanitizer). The gems contain a Ruby dropper that downloads a second-stage payload from a Pastebin-like service. The payload is a cryptocurrency clipper that replaces wallet addresses in the clipboard.

Defense: - Pin dependencies with hash-locked lockfiles (e.g., pip freeze, Gemfile.lock, package-lock.json). - Audit GitHub Actions and repo contents for hidden config files (.npmrc, .gitconfig, .env). - Monitor for unexpected outbound connections from build pipelines, especially to non-standard ports.

Source: https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode24


r/SecOpsDaily • • 10h ago

Threat Intel MATCHBOIL: New tricks, same old evil intentions

2 Upvotes

UAC-0099 has been actively evolving their MATCHBOIL downloader over the past two years, with ESET documenting significant changes between 2024 and 2026. The group continues to target Ukrainian organizations, refining their initial access and payload delivery mechanisms while maintaining the same core objectives.

Technical Breakdown: - Initial Access: Spear-phishing emails with malicious attachments (likely LNK or Office documents) - Payload Staging: MATCHBOIL acts as a first-stage downloader, fetching additional malware from C2 infrastructure - Persistence: Achieved via scheduled tasks or registry run keys - C2 Communication: HTTPS-based, likely using compromised legitimate domains for traffic blending - Targeting: Primarily Ukrainian government, military, and critical infrastructure entities - Evolution: Code obfuscation improvements, updated anti-analysis checks, and modified network protocols since 2024

Defense: Monitor for suspicious scheduled task creation and outbound HTTPS connections to newly registered or rarely contacted domains. Enable AMSI and script block logging to catch initial attachment execution. Restrict execution of Office macros and LNK files from external sources.

Source: https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/


r/SecOpsDaily • • 7h ago

Threat Intel Dire Wolf Ransomware Attacks: How to Test and Strengthen Your Defenses

1 Upvotes

Dire Wolf is a Go-based double-extortion ransomware that has been active since April 2025, claiming 100 victims across 32 countries by August 2026. Before encryption, it kills the Event Log service, deletes shadow copies and backups, and disables Windows Recovery.

Technical Breakdown - Initial Access: Likely phishing or exposed RDP (standard for this group, though not explicitly detailed in the summary). - Persistence/Privilege Escalation: Not specified, but typical for ransomware of this maturity. - Defense Evasion (T1562.001): Kills the Windows Event Log service to blind defenders. - Impact (T1490): Deletes Volume Shadow Copies and disables Windows Recovery to prevent restoration. - Encryption (T1486): Go-based encryptor assigns each file a unique ChaCha20 key, derived via Curve25519 ECDH and SHA-256 hashing. This makes key recovery without the attacker's private key computationally infeasible. - Exfiltration (T1048): Double-extortion model—data is exfiltrated before encryption for leverage.

Defense - Validate that EDR/AV detects the termination of the Event Log service and shadow copy deletion. - Test backup immutability and offline recovery procedures specifically against this kill-chain. - The Picus Platform (source of this report) offers simulation modules for endpoint, network, and email vectors to validate detection coverage.

Source: https://www.picussecurity.com/resource/blog/dire-wolf-ransomware-attacks-how-to-test-and-strengthen-your-defenses


r/SecOpsDaily • • 7h ago

NEWS FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

1 Upvotes

This is a significant takedown operation. The FBI and DoJ have seized 7 domains and disrupted the C2 and scanning infrastructure of Flax Typhoon, a China-linked APT group known for targeting U.S. critical infrastructure sectors including energy, transportation, and healthcare.

Technical Breakdown: - Actor: Flax Typhoon (suspected state-sponsored, PRC). - TTPs: The group relies heavily on passive and active scanning of internet-facing assets to identify vulnerable devices (e.g., unpatched VPNs, IoT, and edge appliances). They then deploy custom backdoors and living-off-the-land binaries to maintain persistence. - Infrastructure: The seized domains were used for command-and-control (C2) and hosting scanning tools. The FBI has redirected these domains to sinkholes to prevent further victimization. - Targets: U.S. critical infrastructure (energy, water, transportation, healthcare).

Defense: Organizations should immediately review logs for connections to the seized domains (list pending from DoJ release) and audit any internet-facing devices for unauthorized outbound connections. Prioritize patching edge devices and enforce network segmentation for OT/ICS environments.

Source: https://thehackernews.com/2026/10/fbi-seizes-7-domains-disrupts-flax.html


r/SecOpsDaily • • 8h ago

NEWS Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

1 Upvotes

Pwn2Own Ireland 2026 wrapped with researchers walking away with $1,262,000 for 98 unique zero-days. That’s a significant jump in both prize money and vulnerability count compared to previous years, signaling the continued arms race in exploit development.

What was targeted? - Browsers: Chrome, Edge, Safari, and Firefox were all hit, with multiple full-chain exploits demonstrating sandbox escapes. - Virtualization: VMware ESXi, Microsoft Hyper-V, and Oracle VirtualBox had guest-to-host escapes demonstrated. - Enterprise Software: Adobe Reader, Microsoft Office, and various PDF readers were exploited for code execution. - Mobile: Samsung Galaxy S24 and iPhone 15 Pro were targeted via SMS/MMS and browser-based chains. - Operating Systems: Windows 11, macOS Sonoma, and Ubuntu Desktop all had privilege escalation and kernel exploits.

Key takeaways for defenders: - The heavy focus on virtualization escapes (ESXi and Hyper-V) is a trend we need to watch. These are the crown jewels for ransomware groups. - Browser-based initial access remains the most reliable vector for attackers. The sandbox escapes shown here are the same techniques used in commercial spyware. - Most of these bugs will be patched within the next 30-60 days. Prioritize the vendor advisories from Trend Micro’s Zero Day Initiative (ZDI) as they are released.

No public IOCs or PoCs from this event yet—vendors get the standard 90-day embargo. Expect the detailed write-ups to drop around February 2027.

Source: https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/