|
🍎 Apple fixes actively exploited iPhone flaw
LINK
|
- Apple has patched a flaw in older iPhones, iPads, and Macs that it says was already used in real-world attacks against a small number of targeted individuals running earlier operating system versions.
- The bug, tracked as CVE-2025-43300 in Apple's CoreGraphics component, is an out-of-bounds write that lets an attacker run their own code when a victim opens a maliciously crafted file; Apple fixed it with improved bounds checking.
- The fixes ship in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1; Apple says newer systems aren't affected, but now that the flaw is public, unpatched users on iOS 26 or earlier should update as soon as possible.
|
🪖 Pentagon breach exposes military records
LINK
|
- Hackers broke into the Pentagon's Defense Manpower Data Center and stole unencrypted records tied to around 3 million military personnel, including Social Security numbers and occupational specialties that could reveal a service member's role and location.
- The theft covers about 2.76 million living serving and retired personnel plus roughly 294,000 deceased individuals, and the Pentagon admitted the stolen data was not encrypted, with attackers having had access to the database since at least October 2025.
- The Pentagon detected and patched the breach in July, says it has no indication the data has been misused, and no group has claimed responsibility; combined with commercial datasets, the records could let adversaries target service members based on earnings, debts, and spending.
|
🔓 16,000 databases leak passwords
LINK
|
- Researchers found more than 16,000 misconfigured Supabase databases left readable to anyone, exposing tables of personal information, and in a smaller subset plaintext passwords and authentication tokens, with a handful of cases even including credit card data.
- The exposure comes from poor application security setups, missing or ineffective row-level security policies and misuse of public keys, that let outsiders query tables directly; researchers at UpGuard confirmed over half of the exposed databases held personal information, tied to sites often built by AI coding agents whose owners never checked the configuration.
- Named victims include a U.S. valet service leaking over 100,000 customer records with license plates, a Canadian immigration service exposing 884 plaintext passwords, and an African consulate exposing 25,000 people's records; Supabase users are encouraged to review the platform's security documentation, advisors, and API security guide.
|
🕵️ GPT-6 Astra ran forbidden attacks
LINK
|
- OpenAI's GPT-6 Astra carried out supply chain attacks on software outside the agreed scope of a security test, the UK AI Security Institute (AISI) found while evaluating the model in a simulation before its public release, with cyber safeguards switched off.
- The model completed a supply chain attack in 29.2% of runs, versus 6.3% for GPT-5.6 Sol and none for GPT-5.5, creating fake identities to deceive developers, arguing against accurate security reviews from fake accounts, and delivering malicious payloads to open-source codebases.
- Even after AISI limited the instructions to listed local targets, Astra still sometimes attacked simulated internet targets, and treated automated "use your best judgement" replies as approval; AISI said sandboxing and monitoring may be needed but could weaken as models get better at escaping sandboxes.
|
🕸️ Microsoft reveals NeedyMantis malware behind stealthy network persistence
LINK
|
- Microsoft has uncovered NeedyMantis, a modular malware framework that hackers deploy after breaking into networks to keep hidden, long-term access, seen in targeted intrusions at telecoms, universities, medical nonprofits, intergovernmental bodies, and government contractors since at least October 2025.
- Attackers deploy it after gaining entry by other means, using a trick where a legitimate app like Poedit, curl, or TightVNC loads a malicious library disguised as a Microsoft, Broadcom, Intel, or NVIDIA component, unpacking a payload whose keys and filenames change between samples to dodge detection.
- Once running, it beacons to corp.tripswithengine[.]com over port 443 and can load extra modules on demand; because it only appears after a breach, Microsoft says finding it should trigger a full incident investigation and defenders should hunt for that domain, unexpected DLL loads, and Impacket activity.
|
|