Research

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Introduction

✉

The signal, without the noise.

Get the daily security brief.

Continuously monitored

Latest intelligence

Research

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across…

Read InfosecFeed brief →
Vulnerabilities

Siemens Mendix Runtime (Update A)

This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. The following versions of Siemens Mendix Runtime are affected: Siemens Mendix Runtime vers:all/* (CVE-2026-7891) CVSS Vendor Equipment Vulnerabilities v3 9.1 Siemens Siemens Mendix Runtime Insecure…

Read InfosecFeed brief →
Vulnerabilities

Botslab G980H Dashcams

Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation. The following versions of Botslab G980H Dashcams are affected: G980H dash cam series 30010_QHG980HN5294SysFW+…

Read InfosecFeed brief →
Vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious…

Read InfosecFeed brief →
Vulnerabilities

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it…

Read InfosecFeed brief →
Vulnerabilities

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process…

Read InfosecFeed brief →
Identity

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the…

Read InfosecFeed brief →
Threats

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released…

Read InfosecFeed brief →
Vulnerabilities

Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control…

Read InfosecFeed brief →
Research

545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against…

Read InfosecFeed brief →
Threats

Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite…

Read InfosecFeed brief →
Vulnerabilities

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS…

Read InfosecFeed brief →
Vulnerabilities

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released…

Read InfosecFeed brief →
Vulnerabilities

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local…

Read InfosecFeed brief →
Vulnerabilities

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on…

Read InfosecFeed brief →
Threats

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group…

Read InfosecFeed brief →
Vulnerabilities

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls…

Read InfosecFeed brief →
Vulnerabilities

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7…

Read InfosecFeed brief →
Identity

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by…

Read InfosecFeed brief →