Daily Recap, this edition highlights supply-chain and application risks, including TrueConf installers being trojanized with backdoors, nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer, and ClickFix macOS stealers draining crypto wallets. It also covers enterprise and exposure concerns such as an Atlassian Rovo one-click flaw leaking Jira and Confluence content, Metabase SQLi zero-day exploitation, UNC6671 vishing targeting personal phones for SaaS data theft, plus breaches at Levi Strauss & Co. and Unlimited Technology Systems.
#TrueConf #RAT #infostealer #ClickFix #macOS #crypto wallets #Atlassian Rovo #Jira #Confluence #Metabase #SQLi #UNC6671 #vishing #Levi Strauss #Unlimited Technology Systems #U.S. Coast Guard #North Carolina ports #DEF CON #Water Watch Center #Adam Cassady #AI patches
#TrueConf #RAT #infostealer #ClickFix #macOS #crypto wallets #Atlassian Rovo #Jira #Confluence #Metabase #SQLi #UNC6671 #vishing #Levi Strauss #Unlimited Technology Systems #U.S. Coast Guard #North Carolina ports #DEF CON #Water Watch Center #Adam Cassady #AI patches
Supply Chain & Malware
- Hackers breached TrueConf to trojanize client installers with backdoors, putting users at risk from compromised software downloads – TrueConf breach
- Nearly 800 malicious npm packages were found delivering a cross-platform RAT and infostealer, highlighting a large-scale open-source supply-chain campaign – npm packages
- ClickFix attacks are distributing a macOS stealer capable of draining crypto wallets, expanding social-engineering-based malware delivery – ClickFix steal
Enterprise Data Exposure
- A critical one-click flaw in Atlassian Rovo let attackers expose enterprise data and trick the AI into sending Jira and Confluence content to outsiders – Rovo flaw, Rovo data leak
- Metabase suffered exploitation of a SQLi zero-day in customer data-theft attacks, showing active abuse of exposed analytics platforms – Metabase zero-day
- UNC6671 used vishing against personal phones to steal SaaS data, underscoring the continued effectiveness of voice-based social engineering – UNC6671 vishing
Web & Application Security
- New CSS-based attacks can bypass webmail defenses to steal passwords and tokens, creating a fresh browser-side phishing risk – CSS attacks
- A new WordPress pre-auth XSS issue could lead to PHP code execution, prompting urgent patching for affected sites – WordPress XSS
Breaches & Theft
- Levi Strauss & Co. said hackers stole corporate data in a cyberattack, adding another major brand to the list of recent breaches – Levi breach
- Unlimited Technology Systems disclosed a breach impacting 3.8 million people, making it one of the largest privacy incidents of the day – UTS breach
- Meta was ordered by a New Mexico judge to pay $567 million in a kids online safety case, marking a major legal blow over child protection claims – Meta penalty
Critical Infrastructure
- The U.S. Coast Guard said it is monitoring a cyberattack that disrupted North Carolina ports, reflecting ongoing risks to maritime logistics – Port attack, Port recap
- Water utilities partnered with a DEF CON offshoot to launch the Water Watch Center, aimed at strengthening visibility into threats against the sector – Water Watch
Policy, AI & Other
- Adam Cassady was confirmed by the Senate as U.S. cyber ambassador, filling a key cybersecurity diplomacy role – Cassady confirmed
- More than half of AI-generated patches were found broken, raising concerns about overreliance on automated code fixes – AI patches
- SecurityWeek also highlighted broader coverage of AI limits, Wall Street targeting, and the North Carolina port incident in its daily roundup – Other news
- Growing Up The Hard Way appeared as a related editorial item with no clear incident details provided – Hard Way