LIVE FEED
Subscribe
//

Category: Exploits

Exploits Coldcard Maker Destroys Vulnerable Inventory After $88M Bitcoin Theft
HIGH Exploits

Coldcard Maker Destroys Vulnerable Inventory After $88M Bitcoin Theft

Coinkite has scrapped remaining stock of its Coldcard hardware wallets after attackers exploited a years-old firmware flaw to drain more than $88…

by Robbie · 2 months ago
Exploits Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy
HIGH Exploits

Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy

A supply-chain compromise of Adform's widely embedded tracking script let attackers silently replace Bitcoin, Ethereum, and TRON addresses copied by site visitors,…

by Robbie · 2 months ago
Exploits Hijacked Hotel Wi-Fi Delivers CornFlake Spyware via Fake Browser Updates
HIGH Exploits

Hijacked Hotel Wi-Fi Delivers CornFlake Spyware via Fake Browser Updates

Microsoft says a Storm-2945 campaign dubbed CaptiveCrunch is hijacking hotel Wi-Fi captive portals to push fake browser updates that install the CornFlake…

by Robbie · 2 months ago
Exploits Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy
HIGH Exploits

Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy

Attackers tampered with a JavaScript file served by ad-tech firm Adform, turning it into a browser-based tool that silently rewrote copied cryptocurrency…

by Robbie · 2 months ago
Exploits Arch Linux Halts AUR Package Adoption After Malware Takeover Surge
HIGH Exploits

Arch Linux Halts AUR Package Adoption After Malware Takeover Surge

Arch Linux has temporarily disabled Arch User Repository package adoption following a wave of malicious takeovers, with researchers linking the campaign to…

by Robbie · 2 months ago
Exploits Dysphoria Botnet Grows to 200,000 Devices Using Blockchain-Based C2
HIGH Exploits

Dysphoria Botnet Grows to 200,000 Devices Using Blockchain-Based C2

Researchers at QiAnXin XLab have tracked a rapidly evolving DDoS botnet called Dysphoria that hides its command infrastructure inside Ethereum and Solana…

by Robbie · 2 months ago
Exploits GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git
HIGH Exploits

GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git

A researcher has published working exploit code for a GitLab vulnerability patched six weeks ago, showing how any authenticated user with push…

by Robbie · 2 months ago
Exploits Hackers Hijack Hotel and Conference Wi-Fi to Steal Microsoft 365 Logins
HIGH Exploits

Hackers Hijack Hotel and Conference Wi-Fi to Steal Microsoft 365 Logins

A DNS hijacking campaign targeting Wi-Fi gateways at hotels and conference centers is redirecting traveling employees to fake Microsoft 365 login pages,…

by Robbie · 2 months ago
Exploits Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases
MEDIUM Exploits

Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases

The fintech parent of Rent-A-Center and Acima told the SEC that attackers used stolen customer data to obtain goods through fraudulent lease-to-own…

by Robbie · 2 months ago
Exploits Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks
HIGH Exploits

Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks

Microsoft says attackers ramped up ACR Stealer campaigns between late April and mid-June, using ClickFix social engineering, WebDAV shares, and MSHTA to…

by Robbie · 2 months ago
Exploits Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat
HIGH Exploits

Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat

Abbott Laboratories is probing unauthorized access to legacy Exact Sciences systems claimed by ShinyHunters, plus a second alleged breach of its LabCentral…

by Robbie · 2 months ago
Exploits North Korean Hackers Hide OtterCookie Malware Inside SVG Flag Images
HIGH Exploits

North Korean Hackers Hide OtterCookie Malware Inside SVG Flag Images

The Contagious Interview campaign is using steganography in SVG files to sneak a four-stage payload past victims lured by fake job postings…

by Robbie · 2 months ago
1 2 3 4 … 7

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.