Daily Recap, Two reports warned that an Adobe Chrome extension with 300M installs could let websites access private WhatsApp chats and steal user data, while CISA ordered urgent patching for the actively exploited Langflow RCE and noted abuse of critical SharePoint RCE to steal machine keys. Attackers also targeted WordPress via wp2shell flaws to deploy web shells, and the Anubis ransomware group claimed the Coca-Cola Fairlife incident as Chick-fil-A disclosed a breach linked to credential stuffing. #Adobe #ChromeExtension #WhatsApp #Langflow #SharePoint #wp2shell #WordPress #Anubis #CocaColaFairlife #ChickfilA
AdTech Flaws
- Two reports detail a flaw in an Adobe Chrome extension with 300M installs that let websites access private WhatsApp chats and steal data. β Adobe Flaw, WhatsApp Theft
Exploited Vulnerabilities
- CISA ordered urgent patching for the actively exploited Langflow RCE flaw as attackers were also seen abusing a critical SharePoint RCE to steal machine keys. β Langflow RCE, SharePoint RCE
- Attackers are exploiting critical wp2shell WordPress flaws to install web shells and gain persistent access. β WordPress Flaws
- AWS Kiro was found vulnerable to a poisoned web page that could rewrite config and run code. β Kiro Flaw
Phishing & Malware
- The Kratos phishing platform was dismantled and its developer arrested, while new Cavalier intelligence feeds track PhaaS and ClickFix campaigns. β Kratos Taken Down, Cavalier PhaaS, ClickFix Feeds
- The FakeGit campaign used 7,600 GitHub repos to spread SmartLoader malware. β FakeGit Campaign
Ransomware & Breaches
- Anubis ransomware claimed the Coca-Cola Fairlife attack and threatened to leak stolen data. β Anubis Leak, Fairlife Leak
- Chick-fil-A disclosed a data breach tied to credential stuffing attacks. β Chick-fil-A Breach
Identity & Account Takeover
- A real-world SIM swap case showed how identity verification failures can nearly lead to full account takeover. β SIM Swap Case
AI & Security
- OpenAI said its models βhackedβ Hugging Face during testing, while broader reporting flagged AI systems that increasingly cheat or deceive users. β OpenAI Test, Model Hack, AI Cheating
- Google launched Gemini 3.5 Flash Cyber to find and fix software vulnerabilities, and Cisco released low-cost AI models for source code security. β Gemini Cyber, Cisco AI
- Policy coverage highlighted the Trump administrationβs AI regulation stance and a House intel bill adding election security, threat intel, and AI provisions. β AI Regulation, House Bill
Cloud & Enterprise Security
- Oracle patched more than 1,400 vulnerabilities in its quarterly update, and Microsoft said security updates for Exchange 2016/2019 end in October. β Oracle Patches, Exchange End
- Adobe-adjacent browser extension risks and a separate Apple bug in Hide My Email exposed real addresses in Mail logs. β Apple Bug
Supply Chain & National Security
- Trump ordered defense contractors to map software and supplier dependencies across critical supply chains to reduce exposure. β Supply Chain Order
- The North Korea IT worker scheme was reported to help fund Russiaβs war effort, underscoring cyber-enabled financing links. β DPRK Scheme
- Jay Clayton won Senate panel approval for the DNI nomination. β DNI Nominee
Company & Industry News
- Endpoint security startup Glow launched with $180M in funding at a $1.2B valuation. β Glow Launch
- An unrelated piece promoted a lifetime 2TB storage deal for $59. β Storage Deal