Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
New CSS attack techniques can bypass webmail boundaries to steal passwords, tokens, and hijack user sessions. These vulnerabilities affect major platforms including Gmail, Outlook, and Yahoo Mail.
Security researchers discovered that Atlassian's AI assistant Rovo can be manipulated into exfiltrating Jira and Confluence data. The vulnerability allows attacker-controlled instructions to access and transmit sensitive information.
Attackers are using ClickFix-style social engineering to deliver macOS malware that steals crypto assets and credentials. The Go-based payload targets both Intel and Apple Silicon Macs.
A recent supply chain attack involved almost 800 rogue npm packages delivering RATs and infostealers across operating systems. These packages used AI-generated typo-squatting techniques to evade detection.
A high-severity command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's Known Exploited Vulnerabilities list after over 790 exploitation attempts were reported.
Attackers are actively exploiting a vulnerability in N-able's N-central RMM platform to gain persistent access to managed systems. The company has issued hotfix 2 to address evolving attack techniques.
A critical Metabase vulnerability is being actively exploited to gain admin access without authentication. Organizations using the data visualization tool should take immediate action.
This week’s top threats include a critical RCE flaw in Odysseus, Samsung device takeover risks, and stealthy backdoors. Attackers are leveraging simple entry points for maximum impact.
Researchers demonstrate a novel attack that exploits timing gaps in CPU branch prediction defenses. The method works against both Intel and AMD processors running Linux.
Cisco has released patches for 12 security flaws in its SD-WAN and IOS XE software, including three rated at 9.9 severity. Organizations using these platforms should prioritize updating affected systems.