Daily Recap, Key exploit and access risks dominated today: Fastjson 1.x RCE flaws are actively exploited with no patch available, while a PoC for an authenticated GitLab command-execution bug and Rockwell fixes for Arena code-execution issues were published. Attackers also pushed zero-click Zimbra phishing, used the BlueNoroff Zoom phishing kit, and leveraged Hermes to automate an intrusion against Thailand’s Finance Ministry, alongside data theft tied to Chick-fil-A and sextortion fueled by ShinyHunters leaks.
#Fastjson #GitLab #Rockwell #Arena #Certighost #Zimbra #BlueNoroff #Zoom #ShinyHunters #Hermes #AgentForger #ChickfilA #ThaiFinanceMinistry
#Fastjson #GitLab #Rockwell #Arena #Certighost #Zimbra #BlueNoroff #Zoom #ShinyHunters #Hermes #AgentForger #ChickfilA #ThaiFinanceMinistry
Exploits & Vulnerabilities
- Fastjson 1.x RCE flaws are being actively exploited with no patch available, while GitLab researchers released a PoC for an authenticated command-execution bug and Rockwell fixed code-execution issues in Arena simulation software. – Fastjson RCE, GitLab PoC, Arena Flaws
- Certighost lets low-privileged Active Directory users impersonate a Domain Controller, raising the risk of full domain compromise. – Certighost Exploit
Phishing & Account Hijacking
- Russia-linked attackers are targeting Zimbra webmail in zero-click phishing campaigns, while BlueNoroff is using a Zoom phishing kit to profile crypto wallets before malware delivery. – Zimbra Alert, BlueNoroff Phish
- Insurance phishing has evolved into real-time account hijacking, showing how attackers now steal sessions as victims interact with fake pages. – Insurance Hijack
- Hackers hijacked hotel Wi-Fi DNS to steal Microsoft 365 credentials, and a separate Microsoft 365 outage was blamed on a maintenance bug. – Hotel DNS Theft, M365 Outage
- ShinyHunters data leaks are being weaponized in a $2,000 sextortion email scam, increasing pressure on victims with recycled breach data. – Sextortion Scam
Malware, Bots & Automation
- Malicious sites are using JavaScript to assemble malware directly in browser memory, helping payloads evade traditional file-based detection. – Browser Memory
- Attackers used an AI agent named Hermes to automate an intrusion against the Thai Finance Ministry, highlighting how AI is being repurposed for offensive operations. – Hermes AI
- Despite repeated takedowns, botnets and residential proxy networks continue to expand, underscoring the resilience of criminal infrastructure. – Botnet Growth
AI Security
- ChatGPT’s AgentForger flaw could let attackers deploy rogue workspace agents through a phishing link, and slopsquatting, phantom domains, and HalluSquatting were identified as the same AI supply-chain attack pattern. – AgentForger Flaw, AI Squatting
- Microsoft and other tech firms are backing more open-source AI, reflecting broader industry momentum around shared model development. – Open-Source AI
Data Breaches & Policy
- Chick-fil-A disclosed a breach affecting more than 13,000 customers, adding to a busy day for credential and data-theft incidents. – Chick-fil-A Breach
- UK cyber policy is staying largely intact as Andy Burnham reappointed a minister despite scrapping the ministry, while industry feedback on CIRCIA pushed for fewer cyberattack-reporting questions. – UK Policy, CIRCIA Feedback