🚨SUPPLY CHAIN ALERT
The official jscrambler npm package (15K weekly downloads) has been hijacked! Version 8.14.0 includes a malicious preinstall script that drops a hidden Rust binary disguised as a .js file on Windows, macOS, and Linux.
The payload is a highly evasive credential and crypto-wallet stealer, featuring advanced anti-analysis tools and kernel-level eBPF instrumentation.
If you installed v8.14.0, consider your system compromised. Immediately rotate all of your credentials!
XRAY-1025905
One actor. 27 weaponized CVEs. 1.4M+ WordPress sites targeted. 🚨
WP-SHELLSTORM is a massive lesson in scaled attacks, leaving 5,700+ active webshells in its wake (alongside a parallel Nacos/Java campaign).
Time to audit your infrastructure, mitigate the risk, and strengthen your posture before automated scanners find you.
🔍 Read the intel: https://t.co/Huk8E7vfkH
#CyberSecurity #WordPress #ThreatIntel #Webshell
Zscaler ThreatLabz has identified malicious websites that use indirect prompt injection (IPI) attacks to manipulate AI agents. These campaigns leverage SEO poisoning to entice AI agents to visit attacker-controlled websites containing hidden instructions designed to influence their behavior. ThreatLabz testing confirmed that several popular LLM models are vulnerable to these attacks and could have been tricked into making fraudulent payments.
Read our full technical analysis here: https://t.co/hi1Xm0xJaQ
⚠️ We are seeing elevated targeted activity against Fortinet products, with a novel feature involving the /api/v2.0/authentication/login pathway targeted post exploitation
Since details about the recent patch bypass are still unclear, be extra vigilant - look out for newly created users starting with the username "fwbadm" followed by 4 alphanumeric characters
Other actors associated with Fortinet authentication bypass exploitation during the past 7 days:
158.94.210.242 Omegatech (🇳🇱)
165.22.225.218 DigitalOcean (🇨🇦)
39.81.66.204 CHINA UNICOM China169 Backbone (🇨🇳)
138.199.53.239 Datacamp (🇷🇴)
179.61.223.49 H4Y Technologies (🇺🇸)
195.133.88.86 GLOBAL CONNECTIVITY SOLUTIONS (🇩🇪)
179.61.223.50 H4Y Technologies (🇺🇸)
72.62.125.35 Hostinger International (🇮🇩)
73.183.20.207 Comcast Cable Communications (🇺🇸)
181.164.178.180 Telecom Argentina S.A. (🇦🇷)
#thesas2025 why not looking for vulnerabilities in a 'only used for critical login from outside' web application. It seems that they succeeded in their challenge.
Nice - CrowdStrike’s blog contains some logs and IOCs
CrowdStrike Identifies Campaign Targeting Oracle E-Business Suite via Zero-Day Vulnerability (now tracked as CVE-2025-61882)
https://t.co/HSAsFUYJYs
Whoa! Turns out a new Microsoft SharePoint zero-day attack is being actively exploited in the wild! It's a new variant of a previously-patched SharePoint bug.
Of course it always happens on weekends.
https://t.co/sYNyaxQaq0
The Justice Department announced charges, an arrest, and raids on dozens of "laptop farms" in the U.S. in an operation to stop a North Korean scheme to get its citizens hired at Western companies https://t.co/79D7JwSf8O
#HuntingTipOfTheDay: @OddvarMoe of @TrustedSec shows how you can run a full C2 implant from Outlook - just setting a few registry keys does the trick.
Any activity concerning these registry keys should be consider suspicious.
Full story here: https://t.co/2KM5PT2uBI
Warning: #CVE-2025-49467 Critical CVSS 9.3 SQL Injection in JEvents component before 3.6.88 and 3.6.82.1 for Joomla. Update to the latest version: https://t.co/XProIdK4r7 #patch#patch#patch
CVE-2025-31324 - CVSS 10 ⚠️🚨 SAP NetWeaver Unauthenticated 🤯 Upload Vulnerability. Affects VCFRAMEWORK 7.50 🏗️ Patch your SAP NetWeaver installs everyone! Threat actors have been using this to upload webshells, don't be next!🔗https://t.co/d87rVHXdBc
🔗https://t.co/P2Heet7h1l
Have you been getting phone calls from long and seemingly random numbers like the ones below? Amnesty believes they could be signs of a zero-click attack targeting Android devices through Voice-over-Wifi or Voice-Over-LTE (VoLTE).
Microsoft has released security updates for 87 vulnerabilities. 4 vulnerabilities are classified as critical, 82 are classified as important and 1 as moderate. 4 are 0-day vulnerabilities, 2 of which are actively exploited. Patches are available. Time to #patch#patch#patch
Warning: #PoC released for #EoP (elevation of privilege) vulnerability in #Microsoft's Remote Registry Service, #CVE-2024-43532 CVSS 8.8. #Patch#Patch#Patch More info: https://t.co/RM7H9UTiEF