Security news.
Today's security news highlights a critical 18-year-old Linux SCTP vulnerability that could allow local users to gain root privileges and escape containers, emphasizing the persistent risks in long-standing codebases. Additionally, new NatJack attacks manipulating NAT tables pose significant threats for session hijacking and DNS spoofing, while widespread Microsoft 365 AitM phishing campaigns target payroll and finance emails. These incidents underscore the importance of rapid patching and vigilance against sophisticated attack techniques.
18-Year-Old Linux SCTP Flaw Allows Root and Container Escape
A use-after-free bug in Linux's SCTP networking code, present since 2008, can lead to full root compromise and container escape. Patches are available in stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148.
New NatJack Attacks Hijack TCP Sessions by Manipulating NAT Tables
Malcolm Stagg disclosed "NatJack" attacks that manipulate NAT connection states to hijack TCP sessions, spoof DNS, expose ports, and exhaust NAT tables, affecting various implementations including Windows.
Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
A widespread email-driven phishing campaign uses adversary-in-the-middle (AitM) techniques and residential proxies to hijack Microsoft 365 accounts, aiming to identify and collect emails from financial personnel.
AI-Assisted HTTP Terminator Discovers Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger's AI-assisted system, HTTP Terminator, found new HTTP desynchronization techniques and a zero-day in Apache Traffic Server after analyzing 30,000 candidate vectors.
Microsoft and Apple Release Fresh Security Updates
Microsoft addressed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass, reinforcing the need for timely updates.
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Malware running in a Windows session can silently use Windows Hello for Business keys to authenticate to Microsoft Entra ID, establishing persistent cloud access and potentially registering new devices.
Truck Brake Controller Safety Recall Included Hidden Security Fixes
NMFTA research revealed that a Bendix EC80 brake controller safety recall also patched remote code execution and denial-of-service vulnerabilities, highlighting potential hidden security updates in safety recalls.
Vishing Extortion Group UNC6671 Rebrands After Making Millions
The vishing extortion group UNC6671, initially known as BlackFile, has expanded its operations under new brands including Redact, Pink, Helix, and Falcon after accumulating millions in extorted funds.