ZeroHour

Search: “Swift”

7 stories in the last 30d

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Sysdig documents a skilled human attacker exploiting Marimo pre-auth RCE CVE-2026-39987 (CVSS 9.3), reaching an SSH bastion in eight seconds without AI tooling.

Sysdig detailed exploitation of CVE-2026-39987 (CVSS 9.3), a pre-authenticated RCE affecting all Marimo versions that came under active exploitation within hours of disclosure. A human operator used a hand-written Python script to harvest an AWS key from Secrets Manager and SSH into a bastion host in eight seconds, issuing 850+ commands over nine hours. Separately, Hunt.io disclosed an XMRig cryptomining campaign compromising 3,562 Redis servers via SLAVEOF rogue replication and AOF authorized_keys injection. Operation CameraSwarm, linked to a single operator, compromised over 14,000 Dahua IP cameras using CVE-2021-33044 and CVE-2021-33045.

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

GreyNoise and Blackpoint tracked an AI-assisted actor using OpenAI Codex and DeepSeek agents to exploit PaperCut flaws across 440+ instances in 48 countries.

A suspected Russian-speaking actor exploited the CVE-2026-81578 authentication bypass and CVE-2026-82078 RCE chain in PaperCut NG/MF, compromising at least 440 instances across 395 organizations in 48 countries, heavily targeting education in the US, UK, France, and elsewhere. The actor used hundreds of AI agents powered by OpenAI Codex and DeepSeek plus tools like Mimikatz, SharpHound, Certipy, Rubeus, and Impacket, reaching domain admin at 12 victims and full domain admin at a US high school within seven minutes. Post-exploitation included registry hive collection and Metasploit/Meterpreter payloads, with origin traced to IP 45.142.193.132.

The Hacker Newsupdated · 6d agofirst · 6d agoThreat actor in the wild 6 sourcesCVE-2026-81578CVE-2026-820781

Srsly Risky Biz: America's Drivers Licence Breach is a National Security Disaster

Dark web service Nexus sold 153 million US and Canadian driver's licenses, linked to identity verification firm IDScan under FBI investigation.

Krebs On Security reported that a dark web service called Nexus sold access to 153 million US and Canadian driver's licenses, claiming over a year of continuous exfiltration from a major identity verification company, with roughly 400,000 new licences added in a single day. Krebs verified the data as genuine and linked the incident via circumstantial evidence to identity verification firm IDScan, whose licences of senior US officials including Secretary of War Pete Hegseth appeared in the database; the FBI is investigating and IDScan has confirmed a breach inquiry. The article argues the data has national security implications, citing how Chinese APT espionage (Anthem, Equifax, Marriott, OPM) and Bellingcat investigations exploited leaked databases. Class action suits are being prepared, and the piece calls for stricter oversight of identity verification firms.

Risky Business News · 7d agoData breach in the wild

Six Chinese AI firms accused of aggressively copying US frontier models

NSA, CISA, and FBI accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation of US frontier models via API abuse.

A joint NSA, CISA, and FBI release alleges six Chinese AI firms have extracted capabilities from US frontier models, including Claude, GPT, Gemini, and Grok, since at least late 2024, likely with Chinese government awareness. Tactics include bulk procurement of premium subscriptions with fraudulent accounts, proxy routing to evade geo-restrictions, and prompt injection to force models to reveal hidden chain-of-thought reasoning. Agencies recommend stronger identity verification, monitoring of anomalous usage, and quietly downgrading or adding noise to responses for suspected distillers, while warning these mitigations could frustrate legitimate users.

Ars Technica · AI · 7d agoAI safety & security in the wild

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Infoblox reports Sable Squirrel spent nearly $7 million on expired domains to redirect traffic to illegal sports streaming, gambling, and malware infrastructure.

Infoblox tracked 50,400 dropcatch domains re-registered daily in gTLDs during H1 2026, nearly 20% of all registrations, with .net and .xyz leading. The threat actor Sable Squirrel has acquired more than 10,000 expired domains supporting Asian sports piracy brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom while promoting betting services like VSBet, ColaScore, and 8xbet. The operation, assessed as Vietnam-based and overlapping the dismantled Xoi Lac TV streaming network, targets users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia via a traffic distribution system, publishes Android apps through suspected compromised Google Play developer accounts, and deployed over 31,000 malware samples including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, and njRAT.

The Hacker News · 9d agoThreat actor in the wild1

Manchester Airports Group breached, millions of customers’ data stolen

Manchester Airports Group confirmed attackers stole customer booking and WiFi signup data affecting about 8.7 million customers across three UK airports.

Manchester Airports Group (MAG) confirmed an unauthorized third party obtained customer data tied to car park, lounge and Fast Track bookings and WiFi sign-ups at Manchester, Stansted and East Midlands airports. Stolen data includes email addresses, phone numbers, vehicle registrations and postcodes; no payment or banking details were held in the affected systems. UK media reported roughly 8.7 million customers affected. The Manage My Booking portal was disabled as a precaution, authorities were informed, and airport operations were not disrupted.

Help Net Security · 17d agoData breach in the wild

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA phishing-as-a-service campaign hit ~4,500 organizations, mostly US, stealing Microsoft 365 passwords and session cookies to bypass 2FA.

ANY.RUN research links the Mirage2FA phishing-as-a-service toolkit to 4,532 unique organization email domains between 2024 and 2026, with the US accounting for 63.7% of victims. The kit uses adversary-in-the-middle login flows to harvest credentials and session cookies, bypassing MFA on Microsoft 365 accounts. Researchers recorded more than 9,000 potential compromise events and estimated 48% of targeted email addresses were potentially compromised. Hijacked sessions extend to SSO-connected services, enabling impersonation, fraud and further compromise.

The Hacker News · 22d agoPhishing & fraud in the wild1