Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Attackers hijacked hotel Wi-Fi networks to push fake browser updates that installed CornFlake malware. The campaign, tracked as CaptiveCrunch, is linked to the threat group Storm-2945.
A newly patched CVSS 10.0 vulnerability in Adobe Campaign Classic could allow attackers to execute arbitrary code without user interaction. Organizations using the platform should apply updates immediately.
A security researcher discovered that Microsoft Copilot for Word can inadvertently copy hidden prompts into new documents. This flaw could lead to unintended data exposure and manipulation in AI-assisted document workflows.
A critical vulnerability in Azure Cosmos DB allowed attackers to bypass security controls and access databases across tenant boundaries. Microsoft has patched the issue after researchers demonstrated full read/write access.
A critical OpenSSL vulnerability allows remote attackers to trigger excessive memory consumption, potentially causing denial of service. The flaw affects SSL/TLS handshake processing in web applications.
This week’s top threats include AI-enhanced hacking techniques, hundreds of Chrome vulnerabilities, and ongoing DNS hijacking campaigns. Trust exploitation remains a core attack vector.
A new macOS malvertising campaign linked to North Korean threat actors uses fake software updates to deliver crypto-stealing malware. The attack leverages full-screen deception techniques to trick users into installing malicious payloads.
A newly patched Ruby on Rails flaw allows unauthenticated attackers to read sensitive server files through malicious image uploads. The vulnerability impacts Active Storage and could leak encryption keys and credentials.
A critical unauthenticated flaw in Cisco's firewall management software is being exploited in the wild. Organizations must act immediately to secure exposed systems.
Amazon attributes the hijacking of popular npm packages 'debug' and 'chalk' to North Korea's Sapphire Sleet group. The attack impacted over 18 packages with billions of weekly downloads.