|
📱 Malicious themes steal iPhone crypto wallets
LINK
|
- Researchers at Socket found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into Vietnamese movie and comic streaming sites to steal crypto wallets from iPhone visitors.
- On iPhones, the injected loader pulls a FUNNULL-hosted WebKit-to-kernel chain that weaponizes two public, patched WebKit bugs (CVE-2025-31277 and CVE-2025-43529, the latter confirmed by Apple as exploited in a targeted attack) against devices running iOS 18.4 through 18.6.x that have not updated.
- After a GPU-process pivot and a kernel escape, already fixed in iOS and macOS 26.1, making it a known unpatched bug used against outdated devices, an August redeployed payload steals keychain wallet seeds and mnemonics from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.
|
💊 McKesson breached via phishing
LINK
|
- McKesson, a major U.S. healthcare and pharmaceutical distributor, has disclosed a breach in which the extortion group ShinyHunters claims to have stolen roughly 284 million patient records after gaining unauthorized access to third-party applications.
- Attackers reportedly started with voice phishing (vishing) calls to employees to compromise Okta single sign-on accounts, then used those credentials to reach McKesson's Salesforce and Snowflake environments, taking about 1 terabyte of data over four days.
- The stolen data allegedly includes names, addresses, dates of birth, Social Security numbers, and medical record numbers; McKesson discovered the incident on August 25, 2026, confirmed the theft, warned of possible intermittent service degradation, and has not yet determined materiality.
|
🔓 Exploit targets Microsoft Exchange servers
LINK
|
- Public exploit code now targets on-premises Microsoft Exchange servers through CVE-2026-62911, an authentication-bypass flaw disclosed after Pwn2Own Berlin 2026, where researcher Orange Tsai chained it to gain SYSTEM-level code execution for a $200,000 reward.
- A proof-of-concept is now circulating, though defenders should treat it as unverified; the bug alone is an elevation-of-privilege issue and only reaches full remote code execution when chained with relay, authorization, and file-write weaknesses.
- The published method coerces NTLM authentication from one Exchange server and relays it to another's MRSProxy service, which lacks Extended Protection for Authentication, to write an ASPX web shell and run commands as SYSTEM; apply Microsoft's August 2026 Exchange updates.
|
📌 Token exploit drains $75M from lender
LINK
|
- Cronos Network shut down its entire blockchain on Sunday after attackers exploited Tectonic, its largest lending protocol, manipulating a token's price to drain roughly $75 million in preliminary losses.
- The attacker pushed TONIC, Tectonic's thinly traded governance token, about 100-fold higher within roughly 20 minutes, then deposited the inflated position as collateral, its 20% collateral factor let the same tokens back far larger loans while the manipulated price held.
- Only about $6 million reached Ethereum before validators, capped at 100 under the network's proof-of-authority setup, coordinated an emergency halt that trapped most funds on-chain; Crypto.com said its app and exchange were unaffected and Tectonic told users not to interact with the protocol.
|
🌐 Hijacked routing delivers malicious update
LINK
|
- Attackers hijacked internet routing for Softaculous's Virtualizor update servers between August 28 and August 30, redirecting traffic to their own systems and pushing a malicious update package to a small number of servers.
- The attackers made an unauthorized BGP announcement for the 162.55.80.0/24 range from AS62390 (NexonHost) via transit provider Zet.net, advertising a more-specific route than Hetzner's legitimate one so networks preferred it while keeping Hetzner's origin number to look inconspicuous.
- Because certificate-validation traffic was also diverted, the attackers obtained a valid Let's Encrypt TLS certificate for virtualizor.com and related domains, so clients saw no warnings; routing is now restored, and administrators should review update activity, package integrity, and logs from the affected period.
|
|