← Latest brief

Security news.

·Morning Brief

Today's security news highlights a critical 18-year-old Linux SCTP vulnerability that could allow local users to gain root privileges and escape containers, emphasizing the persistent risks in long-standing codebases. Additionally, new NatJack attacks manipulating NAT tables pose significant threats for session hijacking and DNS spoofing, while widespread Microsoft 365 AitM phishing campaigns target payroll and finance emails. These incidents underscore the importance of rapid patching and vigilance against sophisticated attack techniques.

THNVULN
4h agoREAD

18-Year-Old Linux SCTP Flaw Allows Root and Container Escape

A use-after-free bug in Linux's SCTP networking code, present since 2008, can lead to full root compromise and container escape. Patches are available in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148.

THNBREACH
4h agoREAD

New NatJack Attacks Hijack TCP Sessions by Manipulating NAT Tables

Malcolm Stagg disclosed "NatJack" attacks that manipulate NAT connection states to hijack TCP sessions, spoof DNS, expose ports, and exhaust NAT tables, affecting various implementations including Windows.

THNPHISHING
5h agoREAD

Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails

A widespread email-driven phishing campaign uses adversary-in-the-middle (AitM) techniques and residential proxies to hijack Microsoft 365 accounts, aiming to identify and collect emails from financial personnel.

THNZERO-DAY
5h agoREAD

AI-Assisted HTTP Terminator Discovers Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger's AI-assisted system, HTTP Terminator, found new HTTP desynchronization techniques and a zero-day in Apache Traffic Server after analyzing 30,000 candidate vectors.

SECURITYWEEK
6h agoREAD

Microsoft and Apple Release Fresh Security Updates

Microsoft addressed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass, reinforcing the need for timely updates.

THNMALWARE
6h agoREAD

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Malware running in a Windows session can silently use Windows Hello for Business keys to authenticate to Microsoft Entra ID, establishing persistent cloud access and potentially registering new devices.

SECURITYWEEKPATCH
5h agoREAD

Truck Brake Controller Safety Recall Included Hidden Security Fixes

NMFTA research revealed that a Bendix EC80 brake controller safety recall also patched remote code execution and denial-of-service vulnerabilities, highlighting potential hidden security updates in safety recalls.

PHISHING
READ

Vishing Extortion Group UNC6671 Rebrands After Making Millions

The vishing extortion group UNC6671, initially known as BlackFile, has expanded its operations under new brands including Redact, Pink, Helix, and Falcon after accumulating millions in extorted funds.

Generated twice daily from public security RSS feeds. Informational only.