A long-standing vulnerability in the Linux SCTP networking code, present since 2008, has been discovered to allow local users to gain root access on the host system. Tencent researchers demonstrated that this use-after-free bug could enable an attacker to escape from a container and access the underlying machine. This issue affects users running older Linux kernels that have SCTP enabled. Fortunately, patches have been released for multiple stable kernel versions, including 7.1.6 and 6.6.148, as of August 3. It's crucial for anyone using affected kernels to update promptly to prevent potential exploitation.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
A vishing extortion group known as UNC6671 has rebranded several times, initially operating under the name BlackFile. The group has expanded its operations by adopting new names including Redact, Pink, Helix, and Falcon, reportedly making millions through their schemes. Vishing, or voice phishing, involves using phone calls to trick individuals into revealing sensitive information or transferring money. This group's activities raise concerns for both individuals and businesses, as they can lead to significant financial losses and a breach of personal data. The ongoing evolution of this group’s branding suggests they are attempting to evade detection while continuing their extortion efforts.
Beacon, a customer relationship management provider for charities, has reported a significant security incident affecting around 1,500 of its client organizations. Unauthorized individuals accessed and likely exfiltrated data from Beacon's CRM databases. This breach puts sensitive information at risk, which could include personal details of charity beneficiaries and staff. Since these charities often handle vulnerable populations, the implications of this breach could be severe, leading to potential identity theft or fraud. Beacon's clients now face the challenge of assessing the impact of this incident and communicating with their stakeholders about the breach.
Schneier on Security
U.S. Immigration and Customs Enforcement (ICE) is reportedly purchasing access to credit card records through data brokers. This means that personal information provided by individuals when they apply for credit cards can be accessed by ICE, raising significant privacy concerns. The data includes details like names, addresses, and transaction histories, which can be used for tracking individuals. This practice affects anyone who has ever applied for a credit card, as their sensitive information may be exposed to government scrutiny without their consent. The implications of this access are serious, as it blurs the line between lawful enforcement and invasive surveillance.
Researchers from VulnCheck have discovered a hidden backdoor in 20 router models, specifically those manufactured by Zbtlink, that allows remote servers to execute commands with root privileges. This backdoor poses a significant risk, as it could allow attackers to take control of affected devices without user consent or knowledge. The issue came to light when Jacob Baines noticed that his router was attempting to connect to an external server unexpectedly. This situation raises concerns for users of these routers, as their devices could be compromised, leading to potential data breaches or unauthorized access to home networks. Users are advised to check if their routers are among the affected models and take necessary precautions to secure their devices.
A recent safety recall for the Bendix EC80 brake controller has turned out to be more than just a precaution; it also addresses serious security flaws. Researchers from the National Motor Freight Traffic Association (NMFTA) discovered that the recall not only targets safety issues but also fixes vulnerabilities that could allow remote code execution and denial of service (DoS) attacks. This is a significant concern for fleet operators and truck manufacturers, as these vulnerabilities could potentially be exploited by attackers, compromising the safety and functionality of vehicles. The recall highlights the importance of addressing cybersecurity threats in automotive systems, especially as vehicles become increasingly connected. Users of the Bendix EC80 brake controller are urged to take immediate action to ensure their systems are updated and secure.
In July 2023, ransomware attacks surged significantly following a quieter second quarter. The finance, technology, and healthcare sectors were the primary targets, with attackers increasingly focusing on these industries due to their sensitive data and critical operations. Comparitech's analysis indicates that the uptick in incidents could pose serious risks to the affected organizations, potentially leading to data breaches and operational disruptions. Companies in these sectors should be particularly vigilant and enhance their cybersecurity measures to protect against these threats. The rise in ransomware activity underscores the ongoing challenges organizations face in safeguarding their systems from malicious actors.
Unlimited Technology Systems experienced a significant data breach that has affected approximately 3.8 million individuals. Hackers accessed sensitive personal information, including medical records and health insurance details, from the company's data center. This incident raises concerns about the security of personal health information and the potential misuse of such data. Affected individuals may face risks related to identity theft and privacy violations, making it crucial for them to monitor their accounts closely. The breach also highlights the need for companies handling sensitive information to strengthen their cybersecurity measures to prevent similar attacks in the future.
Scammers are using AI-generated deepfakes to impersonate popular OnlyFans creators, deceiving fans into sending money for promised live chats that never happen. This scheme targets social media platforms like TikTok, where these fake identities can easily attract followers. After collecting payments, the fraudsters disappear, leaving victims without any recourse. This incident is concerning as it not only exploits the trust of fans but also raises broader questions about the authenticity of online personas. As deepfake technology becomes more accessible, users need to be vigilant about whom they interact with online.
The Hacker News
Researchers have traced the cyber group known as TeamPCP back to 2020, revealing their long-term involvement in compromising internet-facing systems. Initially focused on exploiting these systems, the group has since shifted to targeting software supply chains, raising concerns about the security of widely used applications. The analysis points to shared domains and similar techniques used by TeamPCP over the years, indicating a well-established operation. This ongoing activity emphasizes the need for organizations to bolster their defenses, particularly against supply chain vulnerabilities that could affect multiple software products. Companies should remain vigilant as attackers continue to evolve their methods and targets.
Help Net Security
Recent research shows that the number of U.S. internet addresses responding to queries from fuel tank gauge protocols has dropped significantly. In June, only 2,354 addresses were detected, a steep decline from the usual 4,800 observed monthly for nearly a year. This reduction occurred over three months—April, May, and June—and is notable as it falls below previous annual lows. The findings suggest a rapid decrease in exposure, which is uncommon in this field. This decline is important because it may indicate improved security measures or changes in how these systems are monitored or accessed, potentially reducing the risk of unauthorized access or cyberattacks on fuel management systems.
CrowdStrike has identified a new technique used by attackers to obfuscate shell commands on VMware ESX systems. This method complicates detection efforts by security tools, making it easier for malicious actors to execute unauthorized commands without being noticed. The research highlights the risks associated with virtualized environments, which are increasingly targeted by cybercriminals. Users and organizations running VMware ESX should be particularly vigilant and ensure they have adequate monitoring in place to catch any suspicious activity. The findings serve as a reminder of the evolving tactics used by attackers and the need for continuous improvement in security protocols.
Help Net Security
Isaque Seneda and Gabriel Abrucio have developed a unique web font called ShieldFont, designed to combat AI scraping. This font displays one set of words to users while providing a different set in the page's underlying source code. As a result, when a web scraper attempts to extract text from the HTML, it receives misleading information, which could protect sensitive content from being misused or analyzed by automated tools. ShieldFont was initiated in October 2025 with backing from the type foundry Playtype. This innovation is particularly relevant as businesses and content creators increasingly face challenges from AI technologies that scrape data from websites for various purposes. By using ShieldFont, they may better safeguard their intellectual property and maintain control over how their content is presented online.
Help Net Security
A recent examination of AI-generated spear phishing messages revealed that even seasoned professionals can struggle to identify these sophisticated threats. A banker at a credit union sorted a dozen personalized text messages, and one stood out as particularly convincing, resembling legitimate fraud alerts sent by the bank. This incident underscores the growing risk of AI-driven phishing schemes, where attackers craft messages that closely mimic official communications. As these tactics become more refined, they pose significant challenges for employees who must remain vigilant against such deceptive practices. The potential for falling victim to these scams can lead to unauthorized access to sensitive information, financial loss, and reputational damage for institutions.
Cybercriminals are evolving their tactics faster than law enforcement can respond, creating a significant gap in the fight against cybercrime. Researchers point out that while attackers are increasingly sophisticated and coordinated, law enforcement agencies often work in isolation, which hampers effective collaboration and response. This disconnect means that even as new strategies emerge, many law enforcement organizations struggle to keep up, resulting in a growing challenge in addressing cyber threats. Without improved coordination and information sharing among agencies, the risk of cybercrime will likely continue to rise, affecting businesses and individuals alike. This situation calls for a reevaluation of how law enforcement approaches cybersecurity, emphasizing the need for better collaboration and resources.