Browsing: Cyber Incidents
Introduction: Bucket Hijacking Attack — Why It Matters A newly disclosed cloud attack technique known as Bucket Hijacking Attack has revealed a serious weakness in how several leading cloud providers route data to storage buckets. Security researchers demonstrated that attackers could silently redirect active cloud data streams—including audit logs, telemetry, backups, and replicated data—to storage buckets under their own control without interrupting the affected cloud services. The technique affects cloud environments that rely on globally unique bucket names, including Amazon Web Services (AWS), Google Cloud, and Microsoft Azure. Rather than exploiting software vulnerabilities, the attack abuses cloud storage naming behavior…
Introduction: GPT-5.6 Sol — Why It Matters OpenAI has introduced GPT-5.6 Sol, its newest flagship artificial intelligence model, through a limited preview available only to a select group of trusted organizations. The preview also includes two additional models—Terra and Luna—and forms part of an ongoing engagement with the U.S. government before a broader public release. Unlike previous launches that focused primarily on performance improvements, GPT-5.6 Sol places significant emphasis on cybersecurity. The model incorporates OpenAI’s most advanced safeguards against malicious use, including stronger protections against jailbreak attempts, offensive cyber requests, and misuse for harmful activities. At the same time, it…
TinyRCT Backdoor — Why It Matters A Chinese-speaking advanced persistent threat (APT) group has reportedly deployed a newly identified malware family known as TinyRCT Backdoor in cyber espionage operations targeting government agencies and critical infrastructure organizations across Southeast Asia. According to researchers, the campaign has been attributed to the threat actor CL-STA-1062, which shares operational similarities with the previously tracked group UAT-7237. The campaign demonstrates how sophisticated espionage actors continue to refine their toolsets by combining custom malware, stealthy persistence techniques, and legitimate administrative utilities. Researchers observed compromises affecting at least ten organizations between October and December 2025, highlighting continued…
Introduction: Pedit COW Exploit — Why It Matters A newly disclosed Linux kernel vulnerability, Pedit COW Exploit, is drawing significant attention across the cybersecurity community after researchers demonstrated that it can allow a local, unprivileged user to obtain full root access on affected systems. Tracked as CVE-2026-46331, the flaw resides in the Linux kernel’s traffic-control subsystem and has already been accompanied by a publicly available proof-of-concept (PoC), dramatically increasing the urgency for organizations to patch vulnerable systems. Unlike many privilege escalation vulnerabilities, Pedit COW Exploit does not modify executable files stored on disk. Instead, attackers manipulate cached copies of privileged…
Introduction: Miasma Malware npm Packages — Why It Matters The Miasma Malware npm Packages campaign has emerged as a sophisticated software supply chain attack targeting developers through malicious npm packages associated with the LeoPlatform and RStreams ecosystems. Instead of relying on traditional installation scripts, the attackers abuse the binding.gyp build configuration file to trigger hidden code execution through node-gyp, allowing the malware to bypass many automated security checks. The campaign demonstrates how threat actors continue evolving their techniques to compromise developer environments silently. Once executed, the malware steals credentials from numerous development platforms and cloud services, including GitHub, npm, PyPI,…
Introduction: AWS AiTM Phishing Kit — Why It Matters A sophisticated phishing campaign targeting AWS users has revealed how attackers continue to evolve beyond traditional credential theft. The newly identified AWS AiTM Phishing Kit enables threat actors to steal AWS console credentials and multi-factor authentication (MFA) codes in real time, allowing them to hijack authenticated sessions before security tokens expire. According to Datadog Security Labs, the campaign was active between June 19 and June 23, 2026, and specifically targeted a small number of high-value AWS users, primarily software engineers and engineering leaders in the United States. Instead of simply collecting…
Introduction: Why the Mistic Backdoor Matters A newly discovered stealth malware known as the Mistic Backdoor has emerged as a significant cybersecurity concern after researchers linked it to the KongTuke initial access broker (IAB). Active since April 2026, the malware has reportedly been deployed through malicious ClickFix campaigns alongside ModeloRAT, targeting organizations across multiple industries. Unlike traditional malware, the Mistic Backdoor is designed to remain hidden by executing malicious payloads entirely in memory, making detection significantly more difficult for conventional security tools. Researchers believe the malware is primarily used to establish long-term access before selling compromised networks to ransomware operators,…
Introduction: Lantronix EDS5000 Flaw — Why It Matters The Lantronix EDS5000 Flaw has become an urgent cybersecurity concern after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that attackers are actively exploiting the vulnerability in real-world attacks. The agency has added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting the immediate risk to organizations using affected Lantronix EDS5000 Series devices. The Lantronix EDS5000 Flaw is a critical command injection vulnerability with a CVSS score of 9.8. Successful exploitation allows attackers to execute arbitrary commands with root privileges through the device’s HTTP Remote Procedure Call (RPC) authentication process. Because…
Introduction: Ubiquiti UniFi OS Vulnerability — Why It Matters The Ubiquiti UniFi OS Vulnerability has drawn urgent attention after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three flaws affecting UniFi OS devices to its Known Exploited Vulnerabilities (KEV) Catalog. According to CISA, the most severe issue, CVE-2026-34908, is being actively exploited in the wild. The vulnerability could allow unauthorized users to modify device configurations, potentially opening the door to broader network compromise. Organizations using UniFi gateways, controllers, and related networking products are advised to review patches immediately and apply available security updates. What Is Ubiquiti? Ubiquiti is a…
Introduction: Iran Banking Cyberattack — Why It Matters A major Iran Banking Cyberattack has disrupted card-based banking services at three of the country’s largest lenders, raising concerns about the resilience of critical financial infrastructure. According to reports, customers of Bank Melli, Bank Saderat, and Bank Tejarat experienced interruptions affecting card-related services, including ATM withdrawals, point-of-sale transactions, and mobile banking applications. The Iran Banking Cyberattack was disclosed on June 23 after Iran’s state-owned banking technology provider confirmed that cyberattacks had impacted banking operations. To contain the incident and prevent potential unauthorized access, card-related operations at the affected institutions were temporarily suspended…