Security news.
Today's security landscape is dominated by multiple critical exploitation campaigns, including zero-day attacks targeting popular platforms and widespread credential theft operations. Organizations are urged to patch vulnerabilities promptly and enhance defenses against sophisticated social engineering and supply chain threats.
Magento StyleSmuggler Zero-Day Actively Exploited
A critical zero-day vulnerability dubbed "StyleSmuggler," affecting all versions of Magento and Adobe Commerce, is being actively exploited to deploy backdoors on compromised sites.
MikroTik Routers Under Attack via SSH Authentication Bypass
Attackers are exploiting a critical vulnerability in MikroTik routers to gain full administrative control without authentication through internet-exposed SSH services. Users are advised to patch immediately and assume compromise if vulnerable.
Fake IT Calls Target Executives for Microsoft 365 Data Theft
A widespread data theft and extortion campaign is targeting Microsoft 365 and other SaaS platforms by impersonating IT help desks, using vishing, AiTM token theft, and residential-proxy sign-ins, primarily against executive staff.
PEEP Turns Chrome and Edge into Post-Compromise Backdoors
Researchers have revealed PEEP, a Chromium-based post-exploitation toolkit that bypasses Web Store checks by masquerading as a bookmarks extension to enable host command execution after initial compromise.
Nightmare Eclipse Releases CrowdStrike, Nvidia, Avast Zero-Day Exploits
Proof-of-concept exploits for multiple zero-day vulnerabilities in CrowdStrike, Nvidia, and Avast products have been released by "Nightmare Eclipse," leading to privilege escalation and System-level shells.
BigBear Phishing Service Bypassed MFA at 258 Organizations
The BigBear 2.0 phishing-as-a-service framework has been used to bypass multi-factor authentication and steal over 5,000 Microsoft 365 credentials from 258 organizations.
Rogue ScreenConnect Clients Used in Worm-Like Campaigns
Cybersecurity researchers have observed worm-like activity exploiting ConnectWise ScreenConnect to distribute malicious VBScript payloads to newly connected systems, originating from various initial access methods.
Mathspace Discloses Data Breach Affecting Over 1 Million Users
The online maths learning platform Mathspace has disclosed a data breach impacting more than 1 million students, staff, and parents after its Metabase internal reporting system was compromised.