Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
New vulnerabilities in the widely used U-Boot firmware could allow attackers to crash devices or execute arbitrary code during startup. These flaws affect everything from home routers to enterprise server hardware.
Threat actors breached Injective Labs' GitHub repo to push a malicious npm package designed to steal cryptocurrency wallet credentials. The compromised SDK package伪装成 legitimate telemetry but secretly exfiltrated sensitive user data.
Progress Software has instructed ShareFile customers to immediately shut down Storage Zone Controllers due to a credible security threat. The company has temporarily disabled access to affected accounts as a precaution.
A critical XSS flaw in Zimbra's Classic Web Client allows attackers to execute code through crafted emails. Organizations are urged to update immediately.
GitHub's latest npm update disables install scripts by default to reduce supply chain risks. The release also deprecates granular access tokens that could bypass 2FA.
Microsoft uncovers GigaWiper, a multi-purpose Windows backdoor that bundles disk wiping, fake ransomware, and spyware capabilities. Security teams should monitor for its modular attack patterns.
Attackers are using aged GitHub accounts to map corporate organizations without detection. These ghost accounts enable persistent reconnaissance through GitHub's API.
Multiple high-severity flaws in curl affect various Ubuntu LTS versions, potentially leading to credential exposure, unauthorized access, and denial of service.
Several high-risk flaws in libheif could allow attackers to trigger denial of service or access sensitive data. These issues affect image parsing and memory handling in Ubuntu 26.04 LTS.
A critical flaw in Ubuntu's mailcap package allows attackers to bypass sandbox restrictions. This vulnerability could lead to arbitrary code execution on host systems.