Malvertising Campaign Uses Browser to Assemble Malware
SourTrade malvertising delivers malware in fragments, forcing the browser to reconstruct the payload. It leverages legitimate tools like Bun runtime to evade detection.
Read moreSecurity insights, vulnerability roundups, and updates from the Agent Breach team.
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
SourTrade malvertising delivers malware in fragments, forcing the browser to reconstruct the payload. It leverages legitimate tools like Bun runtime to evade detection.
Read moreAI agent adoption is outpacing security controls, creating new risks. Organizations need intent-aware policies beyond basic visibility.
Read moreA critical vulnerability in Bing Images enabled attackers to execute arbitrary commands with highest privileges on Microsoft's backend servers. The issue stemmed from unsafe processing of user-submitted SVG files.
Read moreA severe flaw in OpenAI's ChatGPT Workspace Agents could have enabled attackers to deploy rogue AI agents through phishing links. The vulnerability, named AgentForger, has been patched as of June 8.
Read moreA new exploit allows low-privilege users to obtain DC certificates and escalate privileges. This vulnerability poses a serious risk to Active Directory environments.
Read moreNorth Korean hackers are using fake Zoom login pages to profile victims' crypto wallets before delivering malware. This advanced phishing campaign combines domain spoofing with targeted social engineering.
Read moreA timing discrepancy in PAM's pam_userdb module could allow attackers to extract sensitive information. Organizations should update their Ubuntu systems immediately to prevent exploitation.
Read moreCyber threats are increasingly hiding in everyday tools and systems. Stay informed on the latest dangers targeting enterprise environments.
Read moreA critical flaw in libinput allows local attackers to inject udev properties and execute code as root. Organizations using Ubuntu-based systems should apply patches immediately.
Read moreA Russian state-sponsored group used a previously unknown Zimbra vulnerability to access sensitive emails and bypass two-factor authentication. The attack highlights critical risks in enterprise webmail systems.
Read more