Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
A new PoC dubbed ShieldBreak targets a patch bypass in Microsoft Defender, potentially granting attackers SYSTEM-level privileges. Security teams should monitor developments closely.
A newly patched vulnerability in SAP Commerce Cloud carries a perfect CVSS score of 10.0, allowing unauthenticated attackers to execute arbitrary code. Organizations using the Data Hub Adapter component should apply updates immediately.
Microsoft identifies Storm-1175 using a new C++-based ransomware strain. The group has shifted from Medusa to StormEncryptor, targeting enterprise systems.
Multiple vulnerabilities in ImageMagick affect several Ubuntu LTS versions, potentially allowing attackers to execute arbitrary code via crafted images.
A supply chain attack on WordPress plugin vendor BdThemes bypassed code modifications by poisoning JSON files. The breach enabled attackers to create unauthorized admin accounts without altering source code.
Cybercriminals accessed industrial control systems through a private cellular network, temporarily shutting down critical infrastructure. The breach highlights risks in remote access configurations for operational technology environments.
An AI system uncovered novel HTTP request smuggling techniques by testing thousands of attack vectors. Researchers also found a critical zero-day vulnerability in Apache Traffic Server.
Attackers are exploiting Microsoft 365 accounts using Adversary-in-the-Middle techniques to access sensitive payroll and financial data. The campaign leverages residential proxies to mask malicious activity as legitimate user traffic.
A new attack vector called NatJack can hijack TCP sessions and spoof DNS by manipulating NAT tables. This affects major platforms including Windows and poses serious risks to enterprise networks.