🛑 WARNING: Bitwarden CLI was compromised in a supply chain attack.
@bitwarden/[email protected] included malicious code after attackers hijacked GitHub Actions, stole secrets, and pushed a tampered version to npm.
🔗 Learn how the attack worked → https://t.co/xqqJ7a9REL
We’ve discovered a massive campaign using 30k-plus hostnames to distribute a #BrowserExtension named "OmniBar AI Chat and Search." This extension overrides the browser homepage and uses an attacker-controlled domain for #SearchHijacking. Details at https://t.co/DOUfJmqLJl
🚨 CVE‑2026‑20965: Azure Identity Token Flaw Enables Tenant‑Wide Compromise via Windows Admin Center
Cymulate Research Labs has disclosed a high‑severity vulnerability in the Azure AD Single Sign‑On (SSO) integration of Windows Admin Center (WAC). The flaw allows an attacker with local administrator rights on a single machine to escalate privileges, execute remote code, and move laterally across all Azure VMs and Arc‑connected systems within the same tenant—even without valid Azure credentials.
Any Azure VM or Arc‑joined machine running an unpatched Windows Admin Center Azure Extension below version 0.70.00 is exposed. Since version 0.69.0.0 was only released in January 2026, this effectively means all deployments with the WAC Azure extension are at risk unless updated.
For defenders, the critical questions now are:
What is the blast radius, and which internet‑facing Azure or Arc‑connected VMs are running the vulnerable WAC Azure extension? These systems could provide attackers with a foothold for remote code execution and lateral movement across the tenant.
The below Defender XDR advance hunting KQL query that helps security teams quickly identify Azure and Arc‑joined VMs running the WAC Azure extension so they can prioritize patching and containment.🫡
#Cybersecurity #WACAzureExtension #RCE #DefenderXDR
If you allow yourself to stagnate technically in a role because the employer allows it, and you don’t need the updated tech skills…
It’s just a matter of time before you get laid off, and discover that you can’t get a position because your skills are dated.
Stay learning.
Due to U.S. telco networks being compromised, today CISA is recommending:
1. Use only end-to-end encrypted communications
2. Enable Fast Identity Online (FIDO) phishing-resistant authentication
3. Migrate away from Short Message Service (SMS)-based MFA
4. Use a password manager to store all passwords
5. Set a Telco PIN
6. Regularly update software
7. Opt for the latest hardware version from your cell phone manufacturer
8. Do not use a personal virtual private network (VPN)
Okay, after finally reading/puzzling through CrowdStrike's Root Cause Analysis (the way the 20 vs 21 inputs thing actually worked is confusing as hell) I can empathize a bit more with CS's people. And I finally think I can explain what happened here in layman's terms:
🧵
In case you didn't know, Microsoft actually publishes a pretty large list of event IDs you should be collecting
Not all are enabled by default though... and many are overly verbose
It's definitely worth parsing some of these for only what you need ;)
https://t.co/jLnh2Y2mKB
So yes, Snipping Tool saves all screenshots to your Pictures folder by default
And no, there is not a GPO to disable this (yet)
For now we can disable this by overwriting C:\Users\*\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
I'll explain
🚨 #BREAKING 🚨
🇺🇸#USA: Hundreds of millions of Advance Auto Parts records allegedly exfiltrated: The threat actor claims to be selling for $1.5 million 3 terabytes stolen from AAP Snowflake.
According to the post, the data includes:
- 380 million customer profiles (name, email, mobile, phone, address, and more)
- 140 million customer orders
- 44 million Loyalty/Gas card numbers (with customer details)
- 358,000 employees
- Auto parts/part numbers
- Sales history
- Employment candidate information with SSNs, driver's license numbers, and demographic details
- Transaction tender details
- Over 200 tables of data
The confirmation or denial of these claims has yet to be verified.
#DataBreach #Snowflake