ZeroHour

Search: “environment”

10 stories in the last 30d

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

BleepingComputer webinar will dissect two Google Workspace breaches caused by malicious OAuth apps and social engineering, hosted September 23 with Material Security.

On September 23, 2026, BleepingComputer will host a webinar with Material Security examining two real attacks that used malicious OAuth applications and social engineering to breach Google Workspace environments. Rather than stealing credentials, attackers persuaded users to authorize malicious apps, gaining access to data through the granted permissions. The session covers first-hour response decisions and which security controls provide the greatest value for fast-growing organizations.

BleepingComputer · 2d agoPhishing & fraud

Microsoft Releases Emergency Patch to Fix RDS Snafu

Microsoft's out-of-band KB5129195 fixes September Patch Tuesday regressions breaking RDS connections, Hyper-V shared folders, and USB audio.

Microsoft released cumulative out-of-band update KB5129195 on September 14, 2026, fixing RDS instability causing failing RDP connections, sign-in issues, and hanging servers. The patch also resolves Hyper-V Plan9 shared-folder failures affecting WSL and Claude Cowork, plus USB Audio Class 1.0 device failures. This is Microsoft's sixth emergency patch after a September Patch Tuesday that fixed a record 974 CVEs.

Infosecurity Magazine · 1d agoAdvisory 3 sources

Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)

SANS guest analyst detonated a RedTail Linux sample from a DShield honeypot, finding process masquerading as php-fpm, monitoring-kill behavior, and a TCP listener.

A DShield honeypot captured multi-architecture RedTail Linux executables (ARM, ARM64, i686, RISC-V, x86-64) deployed via shell scripts. Dynamic analysis of the UPX-packed, statically linked x86-64 sample (SHA-256 63be5f38...d35e) in an isolated Ubuntu 24.04 VM on Proxmox showed it renamed its process via prctl(PR_SET_NAME), killed a filesystem-monitoring process, and opened a TCP listening socket while surviving processes posed as php-fpm or PostgreSQL-like workers. Differential memory images pre- and post-execution were captured from the hypervisor for forensics.

SANS Internet Storm Center · 6d agoMalware in the wild1

Forgery of C2PA on a Pixel 10

Researcher forged a Google Pixel 10 C2PA content credential with genuine signatures, showing root-level attackers can fake photo provenance.

A Hacker Factor blog post demonstrates an AI-generated 'unicorn glitter milk' news photo carrying a valid, cryptographically signed C2PA manifest traceable to Google's Pixel camera certificate chain, passing validation in Adobe Inspect and the CAI Verify tool with a verified timestamp. The author, working with UMBC's PASAWG working group, reported to Google and C2PA in November 2025 that root access on a Pixel device could sign arbitrary images as camera captures; after 90 days without resolution, details were published. The finding undermines C2PA Assurance Level 2 claims made for Pixel 10 Content Credentials.

Lobsters · security · 18h agoResearch

New hardware device can RAM into encrypted memory, expose your data

Researchers built a $200 DDR5 interposer that silently drops memory writes to break TDX, SGX, and SEV-SNP confidential VM integrity, requiring physical access.

Researchers from KU Leuven, ETH Zurich, Durham University, and Google demonstrated DDRop, a hardware interposer costing under $200 that corrupts DDR5 bus commands to silently drop writes to encrypted memory, enabling replay attacks on confidential VMs. Because scalable memory encryption lacks freshness checks, protected VMs keep computing on stale attacker-selected data; on an Intel TDX server the attack forces debug mode for plaintext memory reads or forges attestation reports, succeeding in under two minutes without crashing. Intel and AMD both called the attack out of scope for their cloud threat models, with no mitigation planned, and proposed cache line versioning appears still vulnerable. The full interposer design is being released as open-source hardware.

The Register · Security · 2d agoResearch

AI girlfriend review site's secrets were exposed to the world for three weeks

An AI girlfriend review site left secrets exposed to the public internet for roughly three weeks via unprotected testing and staging environments.

An AI companion review site exposed internal secrets to the world for approximately three weeks through unprotected testing and staging sites. The incident shows that non-production environments are often deployed without the access controls applied to production systems. Specific data types, volumes, and whether anyone abused the exposure were not detailed in initial reporting.

The Register · Security · 20d agoData breach

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

CERT/CC disclosed VU#859658: Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing, letting nearby attackers hijack audio and microphone.

Skullcandy Dime 3 wireless earbuds (model S2DCW, firmware 1.0.0.28) accept Bluetooth Classic BR/EDR pairing requests from unknown devices without the owner activating pairing mode, a flaw linked to CVE-2025-20701 in Airoha Bluetooth audio SDK implementations and tracked as VU#859658 by CERT/CC. Attackers within Bluetooth range who know the device address can bond via the NoInputNoOutput configuration, establish A2DP or HFP/HSP connections, disrupt the owner's active audio session, and potentially capture live microphone audio. Firmware 1.0.0.30 addresses the issue, but Dime 3 earbuds do not support firmware updates through the Skullcandy mobile app, leaving affected users without a known upgrade path.

GBHackersupdated · 6d agofirst · 6d agoVulnerability 2 sourcesCVE-2025-207011

Scans for Proxmox Servers, (Wed, Sep 9th)

SANS observed increased scanning and brute-force attacks on port 8006 targeting unsupported Proxmox VE 7 servers after a recent vulnerability advisory.

SANS Internet Storm Center reported a bump in scans for port 8006 and additional brute-force traffic against Proxmox VE servers following a Proxmox advisory about a vulnerability in older releases. The flaw only affects Proxmox VE version 7, which has been unsupported for a couple of years. Observed activity includes POST requests to /api2/json/access/ticket with root@pam usernames and weak passwords, fingerprinting requests, and POSTs to /api2/extjs/access/ticket; failed logins return 401 status codes and non-TLS POSTs return 308 redirects.

SANS Internet Storm Center · 7d agoExploit / PoC

Phishing Powers 80% of Attacks on US Companies: How SOCs Can Detect It Early

Phishing drives 80% of attacks on US companies; FBI recorded 158,436 BEC victims and over $20B in losses from 2013-2023.

A vendor-authored analysis claims phishing powers roughly 80% of attacks on US companies, citing FBI statistics of 158,436 business email compromise victims and more than $20 billion in reported losses between 2013 and 2023. It describes modern phishing using compromised infrastructure, redirect chains, dynamic pages, and adversary-in-the-middle techniques, including a recent campaign targeting tens of thousands of primarily US users. The piece promotes ANY.RUN Threat Intelligence Feeds and TI Reports, claiming 99% unique high-confidence IOCs, 21-minute faster MTTR, and 30% fewer Tier 2 escalations.

Cyber Security News · 8d agoPhishing & fraud

U.S. Bank says breach claims related to fourth

LockBit claimed data theft from U.S. Bancorp, but the bank attributes it to a fourth-party breach at a contractor's third party, with no impact on its own systems.

LockBit added U.S. Bancorp to its leak site and threatened to release stolen data within two weeks, but the bank investigated and attributed the claims to a fourth-party incident outside its environment. U.S. Bancorp stated there is no evidence its systems, networks, or data repositories were compromised and reported the matter to law enforcement. The bank is the seventh largest in the United States, and LockBit provided no samples to substantiate the claim. The gang, previously subject to a 2024 law enforcement takedown, earned $252.4 million in ransoms through 353 attacks from 2022 to 2024 according to the U.S. Treasury.

The Record · 26d agoRansomware