|
🔓 F5 BIG-IP zero-day under active attack
LINK
|
- F5 and CISA warned today that hackers have been exploiting a critical BIG-IP Access Policy Manager (APM) zero-day, tracked as CVE-2026-94127 (critical, CVSS 9.8), which F5 says it discovered internally and has now patched with hotfixes.
- The flaw lets attackers with no login run code on the appliance by sending malicious traffic, but only when BIG-IP APM is set up as an OAuth Authorization Server on a virtual server with an access policy configured; systems in Appliance mode are also affected.
- Vulnerable versions are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, and F5 published three indicators of compromise whose combined, frequent appearance points to an attack, with CISA urging federal agencies to patch within three days.
|
🎣 Microsoft details EvilTokens takedown after 12,000 accounts hijacked
LINK
|
- Microsoft and law enforcement partners disrupted EvilTokens, a phishing-as-a-service operation that hijacked more than 12,000 inboxes across over 10,000 organizations, seizing 50 websites and disabling over 150 domains tied to its infrastructure.
- Victims were tricked into entering an authentication code on Microsoft's legitimate sign-in page, handing over session tokens without revealing passwords, so access persisted even after a password reset unless the sessions and tokens were also revoked.
- Sold on Telegram for a $1,500 fee plus $500 monthly, the service used AI to summarize mailboxes, find wire transfer discussions and vendor invoices, identify "money movers" and draft messages impersonating trusted contacts to accelerate fraud.
|
🦠 New malware lets AI pick its next move
LINK
|
- Cisco Talos documented CLOSEDQUORUM, a Windows implant that hands control of its next move to a panel of commercial large language models instead of relying on a human-operated command-and-control server to run the intrusion.
- Written in Go and weighing 16.4MB, the malware queries DeepSeek, Qwen, Mistral, and Gemini to vote on a fixed menu, steal data, inject code, or set up persistence, aiming to harvest user credentials and crypto wallets, breaking ties by favoring DeepSeek first.
- Talos never ran it fully against a live target because the copy they examined shipped with placeholder API keys and a dummy webhook, but static analysis confirmed the decision loop works, and they released the open-source CAIRN framework to classify such AI-integrated malware from file metadata.
|
⚠️ SD-WAN server flaw under active attack
LINK
|
- Arista has shipped urgent patches for a maximum severity (CVSS 10/10) flaw in on-premises VeloCloud Orchestrator that attackers are already exploiting as a zero-day to reach privileged internal functionality of the SD-WAN management tool.
- The bug, CVE-2026-93952, is an improper input validation issue in VeloCloud Orchestrator On-Prem; a remote attacker only needs network access to the VCO web interface and the public part of the VeloCloud Edge authentication certificate, with no tenant or operator credentials required.
- Fixed in VCO versions 5.2.3.16 and 6.4.2.8, the flaw threatens the confidentiality, integrity, and availability of the orchestrator; with no definitive indicators of compromise, Arista advises reviewing VCO web access, backend application, and system logs for suspicious activity.
|
🐛 KVM flaw exposes host memory
LINK
|
- A critical flaw in the Linux Kernel-based Virtual Machine (KVM) for ARM64 systems lets attackers break out of a guest virtual machine and read and write the host kernel's memory directly.
- The bug, CVE-2026-89775, affects ARM64 hosts with nested virtualization enabled, where a size calculation returns zero so an invalidation step is skipped, leaving a freed host page still mapped writable into the attacker's guest.
- Disclosed after its embargo expired with no exploitation reported, the flaw is fixed in the mainline Linux kernel; where /dev/kvm has world-writable 0666 permissions, an unprivileged local user could exploit it to gain root, so admins should patch or disable nested virtualization.
|
|