More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Salesforce customers are still bleeding data through a compromised Klue integration. Attackers hijacked a long-dormant Klue credential to mint OAuth tokens and blast nearly 1,000 Salesforce API calls in 15-minute bursts over a full day. Huntress links the breach to the Icarus extortion group, who used session IDs and spoofed Australian mail domains to exfiltrate contacts, quotes and messages. The fix: revoke every Klue secret, audit API query spikes, and lock integration accounts to specific IP addresses.
Almost 9 million Boots customers got a fake βfree sampleβ email that led to a counterfeit checkout page on a hacked Bolivian government site. Romanian threat actors harvested names, addresses and payment details through a bogus customer survey, then ran bulk mailings from a UK business server theyβd compromised. Itβs phishing at scale with real-world brand trust as bait.
A new strain of supply-chain malware is hiding in VSX extensions. GlassWASM, built with TinyGo, sneaks a ChaCha20 routine into two trojanized Open VSX packages (ExarGD.vsblack@0.0.1 and noellee-doc/flint-debug@0.1.1). At runtime it polls a Solana wallet for encrypted C2 addresses, then uses curl or PowerShell to pull down a second-stage payload. Remove those extensions immediately and hunt for the download-and-execute chain rather than chasing rotating hostnames.
Homebrew 6.0 tightens its grips on Linux with Bubblewrap sandboxing enabled by default and adds a tap-trust mechanism that stops third-party Ruby taps until users explicitly opt in. The new brew vulns command checks installed formulae against the OSV database, and every install or upgrade now prompts for confirmation. Lead maintainer Mike McQuaid points out that Homebrewβs curated naming, SHA-256 pinning and build-from-source model have kept it safer than many package ecosystemsβthough itβs phasing out Intel bottles by September 2027.
Questions about this article
No questions yet.