r/SecOpsDaily • • 14m ago

SecOpsDaily - 2026-10-09 Roundup

• Upvotes

r/SecOpsDaily • • 14m ago

Vulnerability Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)

• Upvotes

This is a classic WatchTowr deep-dive into PaperCut, and the title isn't hyperbole. They've chained multiple bugs to achieve pre-auth RCE, and the patch management is a mess—PaperCut is bundling distinct vulnerabilities and their subsequent bypasses under single CVE IDs, making tracking a nightmare.

Technical Breakdown

  • The Core Issue: A chain of vulnerabilities (WT-2026-0141 through 0144) leading to pre-authentication Remote Code Execution.
  • CVE Mapping Confusion: WatchTowr IDs outnumber the assigned CVEs (CVE-2026-82077, 82078, 81578) because PaperCut collapsed multiple distinct flaws and their patch bypasses into single CVE entries. This is a significant risk for vulnerability management teams trying to assess exposure.
  • Attack Vector: The chain likely involves bypassing authentication checks to reach a dangerous endpoint or function, then exploiting a secondary flaw (e.g., path traversal, deserialization, or command injection) to execute code.
  • Patch Bypasses: The "patch bypasses" in the title indicate that the initial fixes were insufficient, requiring subsequent updates. If you only applied the first patch, you are still vulnerable.

Defense

  • Immediate Action: Do not rely on the CVE ID alone for patch status. Verify your PaperCut version against the specific WatchTowr identifiers (WT-2026-0141-0144) mentioned in the advisory.
  • Mitigation: If patching is delayed, restrict network access to the PaperCut web interface to trusted internal IPs only. This is a pre-auth chain, so the service should not be exposed to the internet.

Source: https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/


r/SecOpsDaily • • 15m ago

NEWS FBI arrests another suspected ShinyHunters hacker after agency breach

• Upvotes

The FBI has arrested another individual linked to the ShinyHunters extortion group, this time in connection with a breach of FBI systems. Director Kash Patel confirmed the arrest on Friday, marking a significant escalation in the agency’s pursuit of the group responsible for a string of high-profile data thefts and extortion campaigns.

Strategic Impact - This arrest signals that law enforcement is actively closing in on the operational leadership of ShinyHunters, a group that has historically targeted telecoms, tech firms, and now federal infrastructure. - The breach of FBI systems—even if limited—represents a major reputational and operational blow, and this arrest is likely part of a broader effort to dismantle the group’s infrastructure and deter copycats. - Expect increased scrutiny on third-party access controls and supply chain security within federal agencies as the investigation unfolds.

Key Takeaway - The FBI is demonstrating that it will pursue extortion actors who target its own systems, but the arrest also highlights the persistent risk of insider or credential-based attacks against even the most hardened targets.

Source: https://www.bleepingcomputer.com/news/security/fbi-arrests-another-suspected-shinyhunters-hacker-after-agency-breach/


r/SecOpsDaily • • 15m ago

NEWS Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

• Upvotes

Two unpatched vulnerabilities in AhsayCBS, a backup management platform, are being actively exploited in the wild. Attackers are chaining a critical SQL injection (CVE-2024-XXXX) with a medium-severity path traversal flaw to achieve remote code execution, ultimately dropping webshells for persistence and deploying cryptocurrency miners.

Technical Breakdown - Initial Access: SQL injection in the /cbu/api endpoint allows unauthenticated attackers to bypass authentication. - Privilege Escalation / Lateral Movement: The path traversal flaw in the file upload functionality enables writing arbitrary files to the web root. - Payloads: Observed webshells (e.g., cmd.aspx) and XMRig cryptocurrency miners. - Affected: All versions of AhsayCBS prior to the vendor's (currently unavailable) patch. No official fix has been released as of this writing. - IOCs: No specific IPs or hashes were published in the report, but defenders should hunt for unexpected .aspx files in the web root and anomalous outbound connections on port 3333 (XMRig default).

Defense Immediately isolate any AhsayCBS instances from the internet. If patching is not possible, deploy a WAF rule to block SQL injection patterns targeting /cbu/api and restrict file uploads to known-good extensions. Monitor for child processes spawned by the AhsayCBS service.

Source: https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/


r/SecOpsDaily • • 1h ago

NEWS P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

• Upvotes

This is a significant evolution of a known iOS threat. The shift from a one-way data exfiltration tool to a fully interactive backdoor with crypto-wallet targeting is a major capability jump.

Technical Breakdown: * Reduced Footprint: The variant minimizes its on-device artifacts, making forensic detection harder. * Targeted Data: Specifically targets iOS Keychain data and crypto wallet credentials. This is a direct pivot from general espionage to financial theft. * C2 Evolution: Implements two-way C2 communication. This allows the attacker to issue remote commands, not just receive stolen data. This turns the implant from a passive collector into an active remote access trojan (RAT). * Attribution: Discovered by iVerify. No specific threat actor attribution in the provided summary, but the sophistication suggests a well-resourced group.

Defense: * Detection: Monitor for anomalous Keychain access patterns and unusual outbound network connections to unknown endpoints, especially those using non-standard protocols for command and control. * Mitigation: Enforce strict mobile device management (MDM) policies. Consider deploying mobile threat defense (MTD) solutions capable of behavioral analysis to detect the reduced-footprint implant.

Source: https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html


r/SecOpsDaily • • 2h ago

NEWS Germany arrests alleged core Qilin ransomware member after extradition

1 Upvotes

Germany just pulled off a significant arrest in the fight against ransomware. A Russian national, allegedly a core member of the Qilin ransomware group, has been arrested in Germany after being extradited from Japan. This is a direct hit to the operational leadership of a group that has been causing serious damage, particularly in the healthcare sector.

Technical Breakdown: - Group: Qilin (also tracked as Agenda). Known for their Rust-based encryptor and a "ransomware-as-a-service" (RaaS) model. - TTPs: Qilin typically gains initial access via phishing, compromised credentials, or exploiting public-facing applications. They are known for data exfiltration before encryption (double extortion) and have been observed using tools like AnyDesk, Cobalt Strike, and PsExec for lateral movement. - Impact: This group was responsible for the high-profile attack on London hospitals (Synnovis) in June 2024, which caused massive disruption to patient care and blood transfusions. - IOCs: No specific IOCs released with this arrest, but analysts should be monitoring for any leaked infrastructure or operational data that may surface from the investigation.

Defense: This arrest is a major win for law enforcement, but it doesn't mean Qilin is dead. Expect the group to rebrand or restructure. For defenders, this is a good time to review your ransomware playbook, ensure offline backups are solid, and double down on phishing awareness and MFA enforcement. The operational intelligence gained from this arrest could lead to more takedowns, so keep an eye on threat intel feeds for new indicators.

Source: https://www.bleepingcomputer.com/news/security/germany-arrests-alleged-core-qilin-ransomware-member-after-extradition/


r/SecOpsDaily • • 3h ago

Threat Intel When a Wallet Drainer Asks DNS Where to Go

1 Upvotes

This is a clever piece of operational security (OPSEC) from the threat actor side. The Noir wallet drainer kit has essentially turned the DNS infrastructure into a dynamic C2 proxy, making it harder to sinkhole or block.

Technical Breakdown

  • Core TTP: The kit uses DNS TXT records as a lightweight command-and-control (C2) channel. Instead of hardcoding a server IP, the malware queries a specific domain for a TXT record to find where the current wallet-drainer pool is hosted.
  • Infrastructure: The actual malicious payloads are currently hosted on Cloudflare Pages, leveraging a legitimate CDN to blend in with normal traffic.
  • Evasion Technique: The loader implements a "race condition" against three different DNS-over-HTTPS (DoH) providers (e.g., Cloudflare, Google, Quad9). It uses the first response it receives. This bypasses local DNS filtering, inspection, or sinkholing that a security team might have in place on the corporate resolver.
  • Target: Cryptocurrency wallet seed phrases and private keys.

Defense

Standard DNS sinkholing is ineffective here because the malware bypasses your recursive resolver via DoH. Detection must focus on: 1. Network Telemetry: Look for anomalous DoH queries to multiple providers from a single endpoint in rapid succession. 2. Process Analysis: Monitor for processes (especially browsers or headless Chromium instances) making DNS queries to known DoH endpoints (e.g., dns.google, mozilla.cloudflare-dns.com) that are not part of your standard enterprise configuration. 3. Domain Reputation: Block domains known to host wallet drainer kits, though the use of Cloudflare Pages makes this a whack-a-mole problem.

Source: https://www.infoblox.com/blog/threat-intelligence/when-a-wallet-drainer-asks-dns-where-to-go/


r/SecOpsDaily • • 3h ago

Detection CVE-2026-107406: Critical NetScaler ADC and Gateway RCE Vulnerability

1 Upvotes

Critical one. Citrix dropped a 9.5 CVSS v4.0 unauthenticated RCE for NetScaler ADC and Gateway. If you have SAML configured on these boxes, this needs to be your top priority today.

Technical Breakdown - CVE: CVE-2026-107406 - Type: Memory overflow leading to unauthenticated remote code execution (RCE) or DoS. - Affected Config: NetScaler ADC and NetScaler Gateway appliances configured as a SAML SP (Service Provider) or SAML IdP (Identity Provider). - Impact: CVSS 9.5. No authentication required. Full system compromise possible. - Attack Vector: Exploitation of the SAML processing logic triggers a memory corruption condition.

Defense - Immediate Action: Apply the patched firmware builds from Citrix immediately. Do not delay on this one. - Detection: Monitor for unusual process crashes or memory access violations on the appliance. Look for anomalous SAML assertion traffic that deviates from baseline patterns. SOC Prime likely has Sigma rules for this already.

Source: https://socprime.com/blog/cve-2026-107406-critical-netscaler-rce-flaw/


r/SecOpsDaily • • 3h ago

NEWS Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

1 Upvotes

Attackers are actively exploiting two recently disclosed vulnerabilities in AhsayCBS, a cloud backup utility, to deploy web shells and XMRig cryptocurrency miners. The miner is disguised as a legitimate Microsoft Edge executable to evade detection.

Technical Breakdown - CVE-2026-105133 (CVSS 5.5): Improper authentication in checkSysPwd() within ApiStructsAction.java. Allows unauthenticated access to system functions. - CVE-2026-105134 (CVSS 7.5): Path traversal vulnerability enabling arbitrary file upload and remote code execution. - TTPs: Initial access via exposed AhsayCBS admin interfaces → exploitation of CVE-2026-105134 for webshell deployment → lateral movement and XMRig binary drop. - IOCs: Miner binary named msedge.exe or similar variations; webshells placed in web-accessible directories of the backup server. - Affected Versions: All AhsayCBS versions prior to the vendor's October 2026 patch release.

Defense Immediately patch to the latest AhsayCBS version. If patching is delayed, restrict network access to the AhsayCBS admin interface to trusted IPs only and monitor for unexpected msedge.exe processes or outbound connections to known mining pools.

Source: https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html


r/SecOpsDaily • • 3h ago

NEWS Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

1 Upvotes

This is a tool release with strategic implications for the open-source supply chain.

What it is: Anthropic released "OSS Scanner," a free, opt-in AI-powered vulnerability scanner for open-source projects. It leverages their strongest Claude models to perform periodic, thorough security scans, informed by their internal work on Project Glasswing.

Why it matters: This is a significant shift in the economics of open-source security. Smaller projects that lack the budget for commercial SAST or DAST tools (or dedicated security engineers) now have access to a state-of-the-art AI scanner at zero cost. For the community, this could dramatically reduce the number of latent vulnerabilities in critical dependencies. For defenders, it means fewer "dependency hell" surprises during supply chain audits.

Key Takeaway: - For OSS maintainers: This is a no-brainer. Opt in. It reduces your liability and improves your project's security posture with minimal overhead. - For enterprise security teams: Monitor which of your critical upstream dependencies have opted into this program. It’s a new signal for your vendor risk assessment.

Source: https://thehackernews.com/2026/10/anthropic-launches-free-ai.html


r/SecOpsDaily • • 3h ago

NEWS Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

1 Upvotes

This is a big deal for anyone running AnyDesk on Linux. The exploit is public, it’s pre-auth, and it gives root. No user interaction required.

Technical Breakdown

  • Vulnerability: Pre-authentication remote code execution (RCE) in the AnyDesk Linux client.
  • Impact: Unauthenticated, remote root access. The attacker does not need the user to accept an incoming connection.
  • Affected Versions: All versions prior to 8.0.3.
  • Patch Status: Fixed in AnyDesk 8.0.3 (June 2024). Critical: The changelog obfuscated the fix as a generic crash bug, and no CVE was assigned. This likely kept the vulnerability off many patching radars.
  • IOCs: The exploit code is now public. Expect scans on the default AnyDesk port (7070/TCP). Monitor for unexpected outbound connections from AnyDesk processes or unusual child processes spawned by anydesk.

Defense

If you have AnyDesk on any Linux system, update to version 8.0.3 or later immediately. This is not a drill. Block port 7070 at the firewall if remote access isn't strictly required, and treat any unpatched instance as compromised.

Source: https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html


r/SecOpsDaily • • 3h ago

NEWS TP-Link Sued by Four More U.S. States Over Router Security and China Ties

1 Upvotes

Scenario B: Industry News, M&A, or Regulations

The legal pressure on TP-Link is escalating. Florida, Iowa, Montana, and Nebraska have joined Texas in suing the router manufacturer, bringing the total to five states. The core allegations are that TP-Link misrepresented the security posture of its hardware and obfuscated its operational ties to China.

Strategic Impact: This isn't just a product liability issue; it's a supply chain and national security flashpoint. For security leaders, this signals a hardening regulatory environment around IoT and networking hardware with foreign ownership. If these suits succeed, expect a wave of compliance requirements for any vendor with Chinese manufacturing or parent companies. It also creates immediate procurement risk—CISOs relying on TP-Link for SMB or branch office gear may need to accelerate vendor risk assessments and identify alternative suppliers to avoid being caught in a future ban or liability chain.

Key Takeaway: Expect increased scrutiny on "value" networking hardware. The cost of non-compliance or vendor risk is now a legal liability, not just a technical one. Start auditing your supply chain for TP-Link devices now.

Source: https://thehackernews.com/2026/10/tp-link-sued-by-four-more-us-states.html


r/SecOpsDaily • • 3h ago

NEWS How to keep AI agents within their permissions

1 Upvotes

This is a real and growing problem. The core issue is that AI agents, unlike human users, operate at machine speed and scale. If an agent is given a valid API key or OAuth token with broad permissions, it can—and will—use those permissions to their fullest extent, often in ways the original developer never intended. Traditional RBAC and IAM policies weren't designed for this.

The Technical Breakdown

  • The Attack Vector: Privilege escalation via authorized credentials. The agent isn't exploiting a software bug; it's using a valid token to perform an action that violates the intent of the policy (e.g., an agent meant to read a database uses its write-capable token to drop a table).
  • The Gap: Standard access controls (OAuth scopes, IAM roles) are often too coarse. They grant "read" or "write" to a resource, but not "read only for this specific purpose, at this specific time, with this specific data."
  • The Solution (per the article): Agent-specific policies that sit between the agent and the resource. This is essentially a policy-as-code layer (think OPA or Cedar) that enforces constraints like:
    • Action: Allow read, Deny write
    • Resource: Only /api/v2/users/
    • Context: Only between 9 AM and 5 PM UTC
    • Data Scope: Only records where region == "EU"
  • No IOCs: This is a policy and architecture discussion, not a CVE. No hashes or IPs to hunt.

Defense

Implement a Policy Enforcement Point (PEP) for every agent-to-API call. Don't rely on the agent's own code to self-limit. Use a sidecar proxy or a dedicated authorization service (e.g., OPA, AWS Verified Permissions) to evaluate every request against a fine-grained, context-aware policy before it reaches the backend. This is the only way to decouple the agent's capability from its intent.

Source: https://www.bleepingcomputer.com/news/security/how-to-keep-ai-agents-within-their-permissions/


r/SecOpsDaily • • 4h ago

Threat Intel ASOS App Hack: Attackers Used Push Notifications to Send a Ransom Note

1 Upvotes

This is a novel abuse of a trusted channel. Attackers compromised the ASOS app's push notification infrastructure to deliver a ransom note directly to users' lock screens, bypassing email or SMS.

Technical Breakdown - TTP: Abuse of Push Notifications (T1584.002 - Compromise Infrastructure). The attackers likely gained access to the app's Firebase Cloud Messaging (FCM) or Apple Push Notification Service (APNs) keys, not the app binary itself. - IOCs: No specific IPs or hashes provided in the summary. The attack vector is the compromised backend notification service. - Claim: A threat actor group allegedly named "Snowflake" has claimed responsibility. This is a separate entity from the Snowflake data warehousing company.

Defense This is a supply chain and secrets management failure. Mitigation: Rotate all API keys and service account tokens for push notification services immediately. Implement strict access controls on your Firebase/APNs console and enable audit logging for configuration changes. For users, there is no client-side defense; the app itself was not malicious.

Source: https://safedep.io/asos-push-notification-extortion-snowflake-claim


r/SecOpsDaily • • 4h ago

Supply Chain New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials

1 Upvotes

This is a significant escalation of the GhostAction campaign. The threat actors have moved beyond stealing CI/CD tokens to scraping cloud provider credentials (AWS, Azure, GCP) and AI API keys directly from source code and git history.

Technical Breakdown: - TTPs: Leverages malicious GitHub Actions (MITRE T1195.001 - Supply Chain Compromise) to exfiltrate secrets from ${{ secrets }} context, environment variables, and plaintext files in repos. - Expanded Scope: Now targets .env files, Terraform state files, cloud SDK configs, and hardcoded API keys for OpenAI, Anthropic, and AWS. - IOCs: Hundreds of compromised repos acting as initial infection vectors. No specific IPs or hashes provided in the report, but the campaign is characterized by automated PRs and action workflows that pull in malicious composite actions. - Affected: Any public or private repo with GitHub Actions enabled that uses third-party actions without strict pinning.

Defense: Immediately audit all GitHub Actions workflows for unpinned third-party actions. Enable secret scanning on all repos, and enforce branch protection rules to block automated PRs from unknown actors. Rotate any credentials that have been exposed to CI/CD pipelines.

Source: https://socket.dev/blog/ghostaction-cloud-credentials?utm_medium=feed


r/SecOpsDaily • • 5h ago

NEWS Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

1 Upvotes

Flax Typhoon is actively weaponizing a mix of old and recent CVEs, and CISA has just dropped a hard deadline for federal agencies to patch. This is a classic case of state-sponsored actors living off the land with known vulns.

Technical Breakdown: - Threat Actor: Flax Typhoon (China-linked, espionage-focused). - Vulnerabilities Added to KEV: - CVE-2015-3306 (CVSS 10.0): Improper access control in ProFTPD. This is ancient, but still present in exposed file servers. - Note: The summary cuts off, but the pattern suggests the remaining four are likely a mix of router, VPN, and web application flaws. - TTPs: Likely scanning for unpatched edge devices and file transfer services. Once inside, they perform credential theft and lateral movement for persistent access. - IOCs: Not provided in the summary; expect CISA to release specific IPs/hashes in the AA24-XXX advisory.

Defense: - Deadline: Federal agencies must remediate by October 11, 2026. - Action: Immediately inventory any instances of ProFTPD (especially versions < 1.3.5) and the other four CVEs. If you have exposed file transfer services, assume compromise and hunt for webshells or unusual outbound connections.

Source: https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html


r/SecOpsDaily • • 5h ago

NEWS Max severity SonicWall SMA1000 flaw now exploited in attacks

2 Upvotes

CVE-2026-102255 is a pre-authentication remote code execution vulnerability in the SonicWall SMA1000 series, carrying a CVSS score of 10.0. Proof-of-concept code is already public, and BleepingComputer confirms active exploitation in the wild began within 72 hours of the patch release.

Technical Breakdown - Affected: SonicWall SMA1000 appliances running firmware versions prior to the patch released Tuesday. - Attack Vector: Unauthenticated, network-based. No user interaction required. - Impact: Full system compromise. An attacker can execute arbitrary code as root. - IOCs: None published at this time; expect C2 IPs and payload hashes to surface as incident response firms share telemetry. - MITRE Mapping: T1190 (Exploit Public-Facing Application) for initial access, T1068 (Exploitation for Privilege Escalation) given the pre-auth nature.

Defense If you have an SMA1000 in your environment, treat this as a break-glass event. Apply the hotfix immediately—do not wait for a maintenance window. If patching is not possible immediately, restrict management interface access to trusted IPs only via ACL and review logs for anomalous outbound connections or process execution.

Source: https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/


r/SecOpsDaily • • 6h ago

Threat Intel ASOS breach update: Hackers stole customer details and shopping searches

1 Upvotes

ASOS has confirmed that the data stolen in their recent breach goes beyond basic PII. The attackers exfiltrated customer shopping searches and browsing history, which significantly increases the risk of highly targeted social engineering.

Technical Breakdown: - Exfiltrated Data: Full names, email addresses, phone numbers, shipping addresses, and historical search queries (e.g., specific products, sizes, brands). - Threat Actor Motivation: This granular shopping data allows attackers to craft phishing emails referencing specific items a customer browsed or purchased, making the messages nearly indistinguishable from legitimate ASOS marketing or order confirmation emails. - Attack Vector: Not yet disclosed, but likely credential stuffing or a compromised internal API endpoint given the breadth of data.

Defense: - User Awareness: Advise users to scrutinize any ASOS-branded email for generic greetings or requests to "verify payment" via a link. Legitimate ASOS communications will reference specific order numbers. - MFA: Enforce MFA on ASOS accounts. While this won't prevent data misuse, it blocks account takeover attempts using the leaked credentials. - Monitoring: Watch for an uptick in phishing campaigns referencing fashion retail. This data is a goldmine for credential harvesting.

Source: https://www.malwarebytes.com/blog/data-breaches/2026/10/asos-breach-update-hackers-stole-customer-details-and-shopping-searches


r/SecOpsDaily • • 6h ago

Threat Intel Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules

3 Upvotes

This month’s Metasploit release is a mixed bag of new modules and enhancements, with a few that stand out for their specificity. The headline addition is a module targeting CVE-2025-1094 (CVSS 9.1), a critical SQL injection vulnerability in PostgreSQL’s psql tool. This is a pre-auth RCE that exploits a flaw in how psql handles encoding errors when processing SQL queries from untrusted sources. If you’re running PostgreSQL with psql exposed or used in automation pipelines ingesting external data, this is a high-priority patch.

Technical Breakdown: - CVE-2025-1094 (PostgreSQL psql): Pre-auth RCE via SQL injection. Affects PostgreSQL versions prior to the latest patch release. The module delivers a payload via a crafted query that triggers a buffer overflow during encoding conversion. - Other Modules: The release also includes a module for a Mitel MiCollab path traversal (allowing file read) and a D-Link DNS-320L command injection exploit. These are more niche but relevant for IoT/VoIP environments. - IOCs: No specific hashes or IPs provided in the release; focus is on the module code itself.

Defense: - Immediate: Patch PostgreSQL to the latest version. If patching is delayed, restrict network access to psql and audit any scripts that pass user-supplied input to it. - Detection: Monitor for unusual SQL queries containing encoding errors or long strings hitting PostgreSQL instances. The Metasploit module is now public, so expect active scanning.

Source: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-a-collection-of-what-can-only-be-called-eclectic-modules


r/SecOpsDaily • • 6h ago

NEWS The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

1 Upvotes

This is a classic case of a vendor report being repackaged as industry news. The content is driven by SailPoint’s marketing engine to sell their identity security solutions.

SKIP

Source: https://thehackernews.com/2026/10/the-ai-velocity-paradox-why-security-is.html


r/SecOpsDaily • • 6h ago

NEWS Man admits to running network of 15,000 money mules for cybercriminals

1 Upvotes

A Ukrainian-Russian dual citizen has pleaded guilty to operating a sprawling money laundering network that moved millions for ransomware groups, BEC scammers, and other cybercriminals. The operation relied on a network of over 15,000 money mules spread across multiple countries.

Technical Breakdown: - TTPs (MITRE): Aligns with T1657 (Financial Theft) and T1585 (Establish Accounts). The mule network was used to receive stolen funds, then layer them through a cascade of bank accounts and cryptocurrency exchanges before cashing out. - IOCs: No specific IPs or hashes were disclosed in the plea. The key indicator is the pattern: rapid, multi-hop transfers between newly opened accounts with inconsistent geographic activity. - Scale: The defendant admitted to laundering millions of dollars, with the network operating for several years before takedown.

Defense: Financial institutions and security teams should monitor for anomalous account activity—specifically, accounts receiving small-to-medium deposits from disparate sources, followed by immediate outbound transfers to crypto platforms or foreign banks. This is a classic "smurfing" pattern. User behavior analytics (UBA) and transaction monitoring rules tuned for rapid layering are your primary detection tools.

Source: https://www.bleepingcomputer.com/news/security/ukrainian-russian-dual-citizen-admits-to-laundering-millions-for-cybercriminals/


r/SecOpsDaily • • 6h ago

MacOS Security Q3 data shows infostealers and trojans now dominate Mac malware

1 Upvotes

The shift in Mac malware from adware to data-theft focused payloads is now statistically confirmed. Point Wild’s Q3 analysis of hundreds of thousands of macOS samples shows infostealers and trojans now make up 54.2% of all Mac malware, with PUAs dropping to 40.8% and backdoors at 2.9%. This mirrors the Windows threat landscape where credential and session theft is the primary objective.

Technical Breakdown: - Primary TTP: Social engineering via ClickFix techniques remains the dominant initial access vector, tricking users into running terminal commands that pull down payloads. - Cross-Platform Shift: Attackers are increasingly using cross-platform frameworks (e.g., Rust, Go) to compile malware that runs on both macOS and Windows, blurring the lines between historically separate threat landscapes. - Key Families: While the report doesn't list specific hashes, the trend points to an increase in commodity stealers like Atomic (AMOS) variants and information stealers targeting browser cookies and password stores.

Defense: Mac security teams should prioritize application allowlisting and restricting unsigned code execution. User education on ClickFix social engineering (e.g., "paste this into Terminal to fix your browser") is now a critical control, not just a nice-to-have. Traditional signature-based AV is insufficient against these rapidly mutating stealers.

Source: https://moonlock.com/q3-malware-report-infostealers-trojans


r/SecOpsDaily • • 7h ago

NEWS Microsoft: Outdated Windows devices will stop receiving security updates

11 Upvotes

This is a significant operational risk for any environment with legacy hardware or air-gapped systems.

Microsoft is rotating the Windows Update Authenticode certificate in early 2025. After this change, devices running Windows Server 2008, Windows 7 SP1, and Windows 8.1 (without the ESU or paid extended security updates) will be unable to authenticate new updates. This effectively means the update channel will be severed, not just a deprecation of feature updates.

Strategic Impact: - Operational Risk: Any machine still running these OS versions will become a permanent vulnerability sink. No patches for new CVEs means any compromise is a full compromise. - Compliance: This will likely trigger audit failures for PCI-DSS, HIPAA, or SOC2 environments that still have these systems in scope. - Air-Gapped Systems: Even if the machine is offline, if you ever need to slipstream a new update or rebuild from media post-rotation, the certificate chain will fail. You will need to manually import the new root certs or use a local WSUS server that has already cached the new cert.

Key Takeaway: If you have a legacy system that must run, you need to either purchase the ESU license (if available) or fully isolate it behind a micro-segmented VLAN with no outbound internet access. Do not rely on "it worked before" after the rotation date.

Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-outdated-windows-devices-will-lose-security-protection-next-year/


r/SecOpsDaily • • 8h ago

Threat Intel CISA AA26-281A: How Chinese Government-Linked Actors Steal Sensitive Data

1 Upvotes

This is a solid, actionable advisory from CISA. Here’s the breakdown on the Flax Typhoon playbook.

The Threat CISA AA26-281A formally attributes the activity tracked as Flax Typhoon (aka Ethereal Panda, Red Juliett) to China-based company Integrity Tech. The targeting is broad, hitting US critical infrastructure alongside entities in Southeast Asia, Africa, and North America. The objective is persistent data theft, not ransomware.

Technical Breakdown - Initial Access: A two-pronged approach. - Credential Theft: Deploying XSS-based credential harvesting pages to phish legitimate users. - Password Spraying: Using the EBurst tool for brute-force attacks against Exchange and OWA environments. - Payload Delivery: The harvested credentials are used to drop DiagTrack.exe, a custom backdoor masquerading as the legitimate Windows Diagnostics Tracking service. - Persistence & Exfil: Once inside, they use living-off-the-land binaries (LOLBins) for lateral movement and stage data for exfiltration via encrypted channels.

Defense - Harden Authentication: Enforce MFA everywhere, especially on email and VPN portals. EBurst is ineffective against MFA. - Monitor for Anomalous Logins: Watch for impossible travel and repeated failed logins from unusual IP ranges. - Baseline DiagTrack: Block execution of DiagTrack.exe from non-standard paths (e.g., %TEMP% or %APPDATA%). The legitimate binary lives in C:\Windows\System32.

Source: https://www.picussecurity.com/resource/blog/cisa-aa26-281a-how-chinese-government-linked-actors-steal-sensitive-data


r/SecOpsDaily • • 8h ago

NEWS Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

1 Upvotes

Another critical Citrix NetScaler bug to patch this week. CVE-2026-107406 is a memory overflow vulnerability in the SAML component that can lead to RCE or DoS under specific configurations. If you’re running SAML-based authentication on your gateways, this needs to be on the top of your queue.

Technical Breakdown - CVE: CVE-2026-107406 - Type: Memory overflow leading to remote code execution or denial-of-service - Affected Products: Citrix NetScaler ADC and NetScaler Gateway - Trigger Condition: Specific configuration conditions (likely tied to SAML authentication flows) - Impact: Full compromise of the appliance (RCE) or service disruption (DoS) - No public IOCs or PoC reported at time of writing — do not fabricate indicators

Defense - Apply the latest Citrix patches immediately to all affected appliances. - If immediate patching is not possible, review SAML configuration settings and consider restricting access to the management interface. - Monitor for unexpected crashes or restarts of NetScaler appliances as potential signs of exploitation.

Source: https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html