ZeroHour

Search: “csrf”

50 stories

Tycon Systems TPDIN-Monitor-WEB3

CISA reports three flaws (hard-coded credentials, CSRF, missing authorization) in Tycon TPDIN-Monitor-WEB3 <=2.2.9 enabling MitM, credential theft, or device resets.

CISA published ICSA-26-246-08 for Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior, covering CVE-2026-77847 (use of hard-coded credentials, CWE-798), CVE-2026-82712 (CSRF, CWE-352), and CVE-2026-82684 (missing authorization, CWE-862). Exploitation could enable man-in-the-middle attacks, factory resets, credential wiping, or extraction of system credentials, configurations, and flash contents; the CSRF issue scores CVSS 8.8. No public exploitation has been reported; CISA recommends isolating devices from business networks.

SloppyRAT: A New Tool For Ransomware Attacks

Zscaler details SloppyRAT, a new DLL backdoor delivered via ClickFix lures that stages CastleLoader and CastleRAT ahead of ransomware attacks.

Zscaler ThreatLabz analyzed SloppyRAT, a DLL-based backdoor distributed via ClickFix lures that abuses finger.exe over TCP port 79 to download a batch script. The malware copies curl.exe to download IronPython 3.4.2 from GitHub and executes zlib-compressed Base64-encoded Python to deploy CastleLoader and CastleRAT, then reflectively loads SloppyRAT in memory. It hinders analysis using XOR stack-string obfuscation, a modified affine cipher with modulus 127, and 13 runtime-decrypted code blocks, while communicating with C2 over a reverse SOCKS channel.

Zscaler ThreatLabzupdated · 5d agofirst · 6d agoMalware in the wild 3 sources

Ebyte NA111-M

CISA reports 13 vulnerabilities, including CVSS 9.8 missing-authentication flaws, in Ebyte NA111-M firmware that allow full device compromise.

CISA published ICS advisory ICSA-26-239-05 for Ebyte NA111-M firmware 9013-2-17, listing 13 vulnerabilities tracked from CVE-2026-73125 through CVE-2026-77977. The issues include missing authentication for critical functions, GET requests with sensitive query strings, cross-site request forgery, improper restriction of excessive authentication attempts, and missing authorization. The vendor-assessed CVSS v3 score is 9.8, and successful exploitation could allow an attacker to fully compromise the device. No remediation details are included in the summary text.