security meets culture
GitLab Urges Users to Patch Max Severity Path Traversal Flaw
By Sergiu Gatlan for bleepingcomputer
bleepingcomputer
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
The security flaw, discovered by a security researcher using the 's3ntago' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API.
Unauthenticated attackers can exploit CVE-2026-85706 "under certain conditions" to read arbitrary data-- e.g., credentials, secrets, and sensitive information-- from vulnerable servers.
While GitLab has yet to flag this flaw as exploited in the wild, one day later, cybersecurity company watchTowr reported that attackers have already begun searching for Internet-exposed GitLab servers unpatched against CVE-2026-85706.
"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," it warned.
"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."
Yesterday, GitLab patched a second critical vulnerability tracked as CVE-2026-87719 that stems from an insecure deserialization weakness in the GraphQL subscription serializer.
CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
"These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately," the company warned on Thursday. "GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action."
In May 2023, GitLab addressed another maximum severity path traversal flaw-- CVE-2023-2825-- that exposes sensitive data, including proprietary software code, user credentials, tokens, and files on unpatched servers.
One year later, CISA and the FBI urged software companies to weed out path traversal security vulnerabilities from their products before shipping, saying that such flaws "have been called 'unforgivable' since at least 2007."
More recently, in January, GitLab also patched a high-severity 2-factor authentication bypass affecting community and enterprise editions that enables attackers who know the target's account ID to circumvent 2-factor authentication.
Since November 2021, the US Cybersecurity and Infrastructure Security Agency (CISA) has flagged four GitLab vulnerabilities as exploited in attacks, including 2-- CVE-2021-22175 and CVE-2021-39935-- in February this year.
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
Update September 11, 09:39 EDT: Added watchTowr's report of CVE-2026-85706 probing.
The security flaw, discovered by a security researcher using the 's3ntago' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API.
Unauthenticated attackers can exploit CVE-2026-85706 "under certain conditions" to read arbitrary data-- e.g., credentials, secrets, and sensitive information-- from vulnerable servers.
While GitLab has yet to flag this flaw as exploited in the wild, one day later, cybersecurity company watchTowr reported that attackers have already begun searching for Internet-exposed GitLab servers unpatched against CVE-2026-85706.
"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," it warned.
"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."
Yesterday, GitLab patched a second critical vulnerability tracked as CVE-2026-87719 that stems from an insecure deserialization weakness in the GraphQL subscription serializer.
CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
"These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately," the company warned on Thursday. "GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action."
In May 2023, GitLab addressed another maximum severity path traversal flaw-- CVE-2023-2825-- that exposes sensitive data, including proprietary software code, user credentials, tokens, and files on unpatched servers.
One year later, CISA and the FBI urged software companies to weed out path traversal security vulnerabilities from their products before shipping, saying that such flaws "have been called 'unforgivable' since at least 2007."
More recently, in January, GitLab also patched a high-severity 2-factor authentication bypass affecting community and enterprise editions that enables attackers who know the target's account ID to circumvent 2-factor authentication.
Since November 2021, the US Cybersecurity and Infrastructure Security Agency (CISA) has flagged four GitLab vulnerabilities as exploited in attacks, including 2-- CVE-2021-22175 and CVE-2021-39935-- in February this year.
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
Update September 11, 09:39 EDT: Added watchTowr's report of CVE-2026-85706 probing.
New Android Malware Encrypts Files, Steals Data, and Harasses Victims
By Bill Toulas for bleepingcomputer
bleepingcomputer
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.
Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages.
After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices.
Next, it retrieves its command-and-control infrastructure (C2) domain from GitHub and sends back victim details such as location, carrier, Android version, and device ID. The C2 may send commands through Firebase or WebSockets for execution.
According to Zimperium, Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, Android's official app store, using phishing and social engineering messages to target victims.
Encrypting older Androids
According to mobile security company Zimperium, Mantax Otax encrypts devices running older Android versions. It searches shared storage and encrypts targeted file types using a victim-specific AES key obtained from the C2 server.
The malware then deletes the original files and adds the '.enc' extension to the encrypted copies.
Mantax Otax also replaces local images with ransom notices and opens a full-screen Firebase-hosted chat to facilitate ransom payment negotiations.
Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages.
After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices.
Next, it retrieves its command-and-control infrastructure (C2) domain from GitHub and sends back victim details such as location, carrier, Android version, and device ID. The C2 may send commands through Firebase or WebSockets for execution.
According to Zimperium, Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, Android's official app store, using phishing and social engineering messages to target victims.
Encrypting older Androids
According to mobile security company Zimperium, Mantax Otax encrypts devices running older Android versions. It searches shared storage and encrypts targeted file types using a victim-specific AES key obtained from the C2 server.
The malware then deletes the original files and adds the '.enc' extension to the encrypted copies.
Mantax Otax also replaces local images with ransom notices and opens a full-screen Firebase-hosted chat to facilitate ransom payment negotiations.
Zimperium researchers were able to exploit a misconfiguration in the Firebase C2 server, which exposed the attackers' chats with victims.
Mantax Otax's ransomware module only runs against Android devices running version 9 or older, as the 'Scoped Storage' security and privacy feature in Android 10 and later significantly restricts the encryption capability to the external-files directory.
Spying, spamming, and harassing
Apart from ransomware, Mantax Otax includes spyware, remote control, and harassment features.
The researchers note that the malware can steal lock-screen PINs to maintain persistent access, read SMS and 1-time passwords, access call logs, contacts, browsing history, app lists, Google account information, and location.
It can also extract WhatsApp profiles and messages, as well as Telegram chats, using simulated interactions via Accessibility services.
Additionally, it abuses Android's MediaProjection API to capture screenshots, record MP4 videos, and stream the victim's screen in near real time via the Catbox file hosting service.
Mantax Otax can also capture photographs using the infected device's cameras and upload them to the operator.
Version 2 of the malware added harassment functions such as repeated dialog boxes, full-screen videos, rapid "jumpscare" image overlays, and remotely controlled text-to-speech messages played through the device speakers.
These additional features add an intimidation component to the attacks, which act as a pressure mechanism for the victim to pay the ransom.
Because Zimperium is a Google security partner via the App Defense Alliance (ADA), Mantax Otax is already detected and blocked by up-to-date Android devices with an active Play Protect service.
Users are generally advised not to install APKs from outside Google Play, not to give questionable apps Accessibility permissions, and to only trust reputable publishers.
Skullcandy Dime 3 Earbuds Expose Users to Bluetooth Hijacking
By Bill Toulas for bleepingcomputer
bleepingcomputer
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction.
Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3-- model S2DCW-- uses to handle wireless connectivity and communication between the earbuds and connected devices.
Although Skullcandy says that the security issue was fixed in firmware version 1.0.0.30, regular users have no method to update devices, neither manually nor through the Skullcandy application.
An attacker in close range of a vulnerable device can connect over Bluetooth without a pairing PIN, physical access to the earbuds case, or an approving pairing request.
The CVE-2025-20701 vulnerability was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year.
It is a high-severity missing-authentication problem that affects a broad range of earbud and headphone products from multiple vendors.
Airoha published SDK updates to address the issue on August 4, 2025, and earbud manufacturers subsequently adopted the fixes to plug the security risks.
Apple addressed the flaw for its Beats Studio Buds via a firmware update released this June.
The Skullcandy Dime 3 is a wireless Bluetooth earbud that is very popular with young users looking for affordable products with bass-heavy sound tuning and long-lasting battery.
After receiving a tip from researcher Jacob Nowak, CERT/CC found that CVE-2025-20701 impacts the Skullcandy Dime 3 running firmware version 1.0.0.28.
After pairing, the attacker's device becomes trusted and can automatically reconnect when nearby, enabling them to interrupt the owner's connection, hijack audio playback, access the headset profile, and capture live microphone audio.
The target may hear a "new device paired" notification after the rogue pairing has taken place, but this is easy to miss or dismiss as a momentary connection loss followed by a reconnection.
Skullcandy pushed an update for CVE-2025-20701 in firmware version 1.0.0.30; however, CERT/CC notes that users who bought the earbuds with an earlier firmware release have no way to upgrade to a safe version.
"Existing units running the vulnerable firmware cannot currently be updated by customers through the app," the advisory explains.
"As of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30."
BleepingComputer has been unable to contact Skullcandy about Dime 3 users' inability to upgrade to a safe firmware version, as the company's chatbot does not handle press requests.
Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3-- model S2DCW-- uses to handle wireless connectivity and communication between the earbuds and connected devices.
Although Skullcandy says that the security issue was fixed in firmware version 1.0.0.30, regular users have no method to update devices, neither manually nor through the Skullcandy application.
An attacker in close range of a vulnerable device can connect over Bluetooth without a pairing PIN, physical access to the earbuds case, or an approving pairing request.
The CVE-2025-20701 vulnerability was discovered by ERNW researchers and presented at the TROOPER cybersecurity conference last year.
It is a high-severity missing-authentication problem that affects a broad range of earbud and headphone products from multiple vendors.
Airoha published SDK updates to address the issue on August 4, 2025, and earbud manufacturers subsequently adopted the fixes to plug the security risks.
Apple addressed the flaw for its Beats Studio Buds via a firmware update released this June.
The Skullcandy Dime 3 is a wireless Bluetooth earbud that is very popular with young users looking for affordable products with bass-heavy sound tuning and long-lasting battery.
After receiving a tip from researcher Jacob Nowak, CERT/CC found that CVE-2025-20701 impacts the Skullcandy Dime 3 running firmware version 1.0.0.28.
After pairing, the attacker's device becomes trusted and can automatically reconnect when nearby, enabling them to interrupt the owner's connection, hijack audio playback, access the headset profile, and capture live microphone audio.
The target may hear a "new device paired" notification after the rogue pairing has taken place, but this is easy to miss or dismiss as a momentary connection loss followed by a reconnection.
Skullcandy pushed an update for CVE-2025-20701 in firmware version 1.0.0.30; however, CERT/CC notes that users who bought the earbuds with an earlier firmware release have no way to upgrade to a safe version.
"Existing units running the vulnerable firmware cannot currently be updated by customers through the app," the advisory explains.
"As of this writing, there are no known consumer-accessible methods to update an existing unit from the affected firmware version 1.0.0.28 to version 1.0.0.30."
BleepingComputer has been unable to contact Skullcandy about Dime 3 users' inability to upgrade to a safe firmware version, as the company's chatbot does not handle press requests.
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
By Ravie Lakshmanan for The Hacker News
The Hacker News
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.
Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their release.
One aspect worth highlighting is that users cannot leave public reviews or star ratings for apps that are available in Early Access. This has opened the door to a new kind of abuse where threat actors are pushing thousands of Early Access applications with deceptive content, including fake casino games and reward apps, as well as misleading utilities and titles that may infringe on 3rd-party trademarks.
Among the identified apps is a Grand Theft Auto imitator named "Vice Streets: Open World"-- APK package:com.gamblechaos.withfriends.game-- which has more than 1 million downloads. The game has no reviews or ratings. It's currently no longer available on the Google Play Store, although it's not clear if it was taken down by Google or by the uploader themselves.
"The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted," Bitdefender said in a statement.
Because users cannot leave critical reviews or poor ratings, the traditional trust signals no longer apply, allowing such apps to gain traction. These apps are said to be promoted through TikTok, Facebook, and other social media platforms using bogus ads that include videos featuring celebrity deepfakes generated using artificial intelligence (AI).
"A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot," the Romanian cybersecurity company said in a report shared with The Hacker News.
"Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive."
The end goal is to generate illicit revenue by serving ad after ad. Another advantage that these Early Access casino-oriented apps have is that they allow them to sidestep many of the regulatory requirements legitimate gambling applications are required to comply with.
To get around the licensing, geofencing, and age verification restrictions, the casino-style apps masquerade as casual slot and puzzle games and are aggressively promoted via ads on social media platforms that lead unsuspecting users to Early Access apps in the Google Play Store or directly to various gambling websites.
Further analysis indicates that the lures used for these apps go beyond casino games, slot machines, and fake reward apps to include PDF readers, QR scanners, phone trackers, utility apps, and trademark-themed games.
Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their release.
One aspect worth highlighting is that users cannot leave public reviews or star ratings for apps that are available in Early Access. This has opened the door to a new kind of abuse where threat actors are pushing thousands of Early Access applications with deceptive content, including fake casino games and reward apps, as well as misleading utilities and titles that may infringe on 3rd-party trademarks.
Among the identified apps is a Grand Theft Auto imitator named "Vice Streets: Open World"-- APK package:com.gamblechaos.withfriends.game-- which has more than 1 million downloads. The game has no reviews or ratings. It's currently no longer available on the Google Play Store, although it's not clear if it was taken down by Google or by the uploader themselves.
"The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted," Bitdefender said in a statement.
Because users cannot leave critical reviews or poor ratings, the traditional trust signals no longer apply, allowing such apps to gain traction. These apps are said to be promoted through TikTok, Facebook, and other social media platforms using bogus ads that include videos featuring celebrity deepfakes generated using artificial intelligence (AI).
"A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot," the Romanian cybersecurity company said in a report shared with The Hacker News.
"Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive."
The end goal is to generate illicit revenue by serving ad after ad. Another advantage that these Early Access casino-oriented apps have is that they allow them to sidestep many of the regulatory requirements legitimate gambling applications are required to comply with.
To get around the licensing, geofencing, and age verification restrictions, the casino-style apps masquerade as casual slot and puzzle games and are aggressively promoted via ads on social media platforms that lead unsuspecting users to Early Access apps in the Google Play Store or directly to various gambling websites.
Further analysis indicates that the lures used for these apps go beyond casino games, slot machines, and fake reward apps to include PDF readers, QR scanners, phone trackers, utility apps, and trademark-themed games.
"Google's Early Access program remains a valuable tool for developers testing new ideas," Bitdefender said. "Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community's strongest defenses against deceptive software."
The Hacker News has contacted Google for comment, and we will update the story if we hear back.
The disclosure coincides with the emergence of multiple malware families targeting Android:
- Hagaseca, a remote access trojan spread via the THost9 loader that contains a worm component, which scans exposed Android Debug Bridge (ADB) services and installs the malware for persistence and remote control through shell execution, file transfers, tunneling, and downloadable modules.
- Mantax Otax, a hybrid mobile malware that brings together comprehensive spyware capabilities and ransomware functionality, allowing the operator to steal sensitive data, encrypt it on targeted older Android versions-- Android 9 or earlier-- and demand a ransom payment by locking the device screen. Language indicators and files from the victims suggest the activity is primarily focused on Indonesian targets.
- StreamRat, which abuses Android's accessibility services and the MediaProjection API to control infected devices, serve overlays, and harvest sensitive data. The malware targets Spanish-speaking users through Meta and TikTok ads to direct users to counterfeit sites by masquerading as a free TV-streaming service named StreamTV Esp.
The development also coincides with GoldFactory's use of the Gigabud banking trojan to install a companion Android app called Vwork, a weaponized fork of Shelter, to clone a target app inside a work profile with the goal of conducting financial fraud.
"With full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim's phone while a black screen hides what is happening," Group-IB said. "A cloned environment is used to evade fraud protection controls."
ShinyHunters Hackers Claim Breach of Florida 'DAVID' DMV Database
By Lawrence Abrams for bleepingcomputer
bleepingcomputer
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein's DMV record, including his address and registered vehicles.
DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver.
"The Driver And Vehicle Information Database (DAVID) is a multifaceted database that affords immediate retrieval of driver and motor vehicle information that is indispensable for law enforcement and criminal justice officials," reads a description on the FLHSMV website.
"DAVID is the primary reporting mechanism for Fatalities and Serious Bodily Injury (FSBI)."
Last night, ShinyHunters added FLHSMV to its data leak site, warning that it would leak the allegedly stolen data if the agency did not negotiate with them.
As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein's DMV record, including his address and registered vehicles.
DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver.
"The Driver And Vehicle Information Database (DAVID) is a multifaceted database that affords immediate retrieval of driver and motor vehicle information that is indispensable for law enforcement and criminal justice officials," reads a description on the FLHSMV website.
"DAVID is the primary reporting mechanism for Fatalities and Serious Bodily Injury (FSBI)."
Last night, ShinyHunters added FLHSMV to its data leak site, warning that it would leak the allegedly stolen data if the agency did not negotiate with them.
As proof of the breach, the threat actors released a screenshot of Jeffrey Epstein's record in the DAVID system. This record includes the person's address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles.
The system also has tabs for additional information, including driver's license transactions, addresses, insurance, prior vehicles, and parking permits.
ShinyHunters told BleepingComputer they breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.
Using this access, the threat actors say they iterated through the records by IDs and then downloaded the associated HTML and images for the drivers. This allegedly allowed them to steal over 200,000 data records since the breach began on September 3rd.
The threat actors told BleepingComputer that they have since lost access to the database and that the password-reset flaw used to compromise accounts is being patched.
BleepingComputer contacted FLHSMV and the FBI yesterday about the incident and will update the story if we receive a response.
A source told BleepingComputer that the threat actors are also targeting other states' DMV platforms using social engineering attacks.
When asked whether they are targeting additional DMVs, ShinyHunters told BleepingComputer they expect to announce other breaches over the coming weeks.
Who is ShinyHunters
ShinyHunters is an extortion gang known for targeting online web applications and cloud SaaS environments in data theft attacks.
The name ShinyHunters has long been associated with numerous threat actors who have conducted data breaches since 2018.
Over the past year, threat actors using the ShinyHunters name have become one of the most prolific groups that conduct data theft and extortion attacks against companies worldwide.
Initially focusing on Salesforce and other cloud SaaS environments, the threat actors are linked to a growing number of breaches involving companies such as Google, Cisco, PornHub, and online dating giant Match Group.
The extortion gang commonly breaches 3rd-party integration companies and uses stolen authentication tokens to access connected SaaS environments and steal customer data.
More recently, the threat actors have been conducting voice phishing (vishing) attacks targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, where they impersonate IT support staff to trick employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites.
As BleepingComputer first reported, the ShinyHunters group has also adopted device code vishing attacks to obtain Microsoft account authentication tokens.
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
The extortion gang was also behind a massive data-theft attack on Instructure Canvas in May that caused significant outages to the platform. The company eventually reached an "agreement" with the threat actors to prevent the data stolen in a recent breach from being leaked online.
Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.
However, even with these arrests, threat actors using the ShinyHunters name remain a threat to enterprises worldwide.
WeWorm: The First Zero-Click Worm to Spread Through WeChat Calls Across iOS and Android
ChatGPT Flaw let a Planted Prompt Send a Victim's Gmail Data
to Another Account
By Swati Khandelwal for The Hacker News
The Hacker News
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual.
In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel between the two. The reply the user saw said nothing about it.
Check Point said the same channel could also copy out the chat history and the files in that conversation.
How much an attacker could take depended on what the session could already access, including its data, tools, other connected apps, and permissions.
The instruction had to be in the conversation before any of this worked. Check Point named three ways to get it there: a prompt the user pastes in, a shared ChatGPT conversation the user opens, or a custom GPT that holds it in its builder instructions, which are not shown to the user.
After that, one ordinary message was enough to start it. Check Point wrote the instruction so that ChatGPT, in Thinking mode, ran 2 streams of work in the same turn.
ChatGPT answered the user. At the same time, it checked a hidden mailbox for a task from the attacker, carried out that task using the tools in the user's session, and sent the result back. The instruction told the model to keep the 2 streams separate, so the hidden task never appeared in the visible answer.
The only sign that an app had been used was a small "Talked to Gmail" label above the answer. It recorded a read that had already happened and gave the user no chance to allow or refuse it.
Nothing asked the user first because of how connected apps work by default. OpenAI's documentation lists Important actions as the default permission, which allows ChatGPT to read from an app without prompting. ChatGPT asks only before actions that could have a real effect outside ChatGPT, expose sensitive information, or be hard to undo.
In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel between the two. The reply the user saw said nothing about it.
Check Point said the same channel could also copy out the chat history and the files in that conversation.
How much an attacker could take depended on what the session could already access, including its data, tools, other connected apps, and permissions.
The instruction had to be in the conversation before any of this worked. Check Point named three ways to get it there: a prompt the user pastes in, a shared ChatGPT conversation the user opens, or a custom GPT that holds it in its builder instructions, which are not shown to the user.
After that, one ordinary message was enough to start it. Check Point wrote the instruction so that ChatGPT, in Thinking mode, ran 2 streams of work in the same turn.
ChatGPT answered the user. At the same time, it checked a hidden mailbox for a task from the attacker, carried out that task using the tools in the user's session, and sent the result back. The instruction told the model to keep the 2 streams separate, so the hidden task never appeared in the visible answer.
The only sign that an app had been used was a small "Talked to Gmail" label above the answer. It recorded a read that had already happened and gave the user no chance to allow or refuse it.
Nothing asked the user first because of how connected apps work by default. OpenAI's documentation lists Important actions as the default permission, which allows ChatGPT to read from an app without prompting. ChatGPT asks only before actions that could have a real effect outside ChatGPT, expose sensitive information, or be hard to undo.
A user who wants to be asked every time can switch to Always ask. In Business, Enterprise, and Edu workspaces, admins choose which actions each app may take and who may use it. Apps are on by default on Business plans and off by default on Enterprise and Edu.
Check Point said it disclosed the finding to OpenAI and that OpenAI confirmed the internal service behind the channel had been taken offline. There is no update for users to install.
The channel ran between the containers where ChatGPT runs code. ChatGPT builds one for each conversation when a task calls for it.
OpenAI's documentation says the Python environment ChatGPT uses for data analysis cannot make requests to the web or to outside APIs. Check Point said containers built for separate conversations, including ones under different accounts, had no direct path to each other either.
All of them could reach one internal service. ChatGPT sometimes needs to install extra Python or npm packages. Rather than allowing the containers to reach public package repositories, each was allowed to talk to an internal JFrog Artifactory instance that fetched packages for it.
That instance let a container attach named values, called properties, to a stored file and read them back. The credentials the container held for read access were also enough to write those properties. They sat in environment variables, where code that ChatGPT ran could pick them up. The code did not need to steal a separate secret or escalate privileges.
The properties were not kept separate by account. From a container under one account, Check Point attached a property named chatgpt_test_ts, containing the current time, to a cached file. In a conversation under a different account, it requested that file's properties and received the same name and value.
A property can carry plain text or Base64, and anything too large for one can be split across several and reassembled at the other end. That turned the package service's metadata into a shared clipboard between containers that were not supposed to reach each other.
This is the second channel out of the same part of ChatGPT that Check Point has reported. In March, it described one that used DNS lookups to send conversation data to an external server, and said OpenAI fixed it on February 20.
The case is separate from the Hugging Face incident, in which OpenAI's own models turned an internal Artifactory instance into a message board during the company's security tests.
Check Point said the mechanism it found was different and described both as cases in which "a shared internal service became an unintended communication layer" across environments meant to stay isolated.
Check Point dated its work to June 2026 and did not say when the channel stopped working, so the report does not show how long it was open.
DoppelCart Fraud Network Uses 119,000 Fake Shops to Steal Credit Cards
By Bill Toulas for bleepingcomputer
bleepingcomputer
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD.
German cybersecurity startup Nebty discovered DoppelCart and describes it as the largest publicly documented fake-shop cluster by domain count, far surpassing the second-largest, "BogusBazaar," which operated a network of 75,000 sites that recorded an estimated 850,000 fraudulent transactions.
The company's latest scans show that more than 105,000 DoppelCart shops are still active.
Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends.
The sites impersonate legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes loading assets directly from the real company's servers.
Scheungraber says that the shops mimic 44,182 different brands, with a median of 2 clones for each.
However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.
The fake sites advertise big discounts of up to 65% in many cases to lure bargain-hunting shoppers.
Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD.
German cybersecurity startup Nebty discovered DoppelCart and describes it as the largest publicly documented fake-shop cluster by domain count, far surpassing the second-largest, "BogusBazaar," which operated a network of 75,000 sites that recorded an estimated 850,000 fraudulent transactions.
The company's latest scans show that more than 105,000 DoppelCart shops are still active.
Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends.
The sites impersonate legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes loading assets directly from the real company's servers.
Scheungraber says that the shops mimic 44,182 different brands, with a median of 2 clones for each.
However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.
The fake sites advertise big discounts of up to 65% in many cases to lure bargain-hunting shoppers.
When testing several checkout pages in the DoppelCart cluster, Nebty found code that collected sensitive information related to payment cards and their holders:
- Card numbers
- Expiration dates
- Security codes
- Cardholder names
- Email addresses
- Phone numbers
- Physical addresses
Each data field is transmitted over WebSockets to the command-and-control (C2) in real time, Netby says in a report shared with BleepingComputer.
The checkout code can also relay the 1-time confirmation code issued by a victim's bank, which the attackers may use to bypass security protections.
Nebty says some of the fake stores show the impersonated brand's legitimate support address, leading victims who didn't receive their purchases to contact the real company.
Scheungraber says that the company tried to contact the main hosting provider for DoppelCart sites but received no response.
Separately, Nebty created a searchable database to help companies identify DoppelCart impersonation and brand abuse and take appropriate action to protect themselves.
Magento StyleSmuggler Zero-Day Exploited to Deploy Linux Backdoor
By Bill Toulas for bleepingcomputer
bleepingcomputer
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
The first exploitation incident was recorded on September 4 on a target running the latest security updates.
E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release.
Magento is a popular open-source e-commerce platform by Adobe installed on more than 160,000 websites, including 14,000 of the top 1 million sites.
Linux backdoor
The exploit Sansec observed in the wild abuses Magento's template system through PHP code injection to generate a fake "failed-payment" email, which triggers code execution.
Successful exploitation installs a small Rust-based backdoor as a background process, disguised as [kworker/u:8:0]. Newer versions disguise the process as fc-cache and copy it to ~/.cache/fontconfig/fc-cache.
According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes for persistence.
Although Sansec did not observe any follow-on activity, the malware can communicate with remote infrastructure and receive commands.
The researchers note that earlier samples of the backdoor used TLS/WebSockets to communicate with the command-and-control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP).
They send UDP packets to port 123 and use hostnames that resemble time-syncing infrastructure, helping to mask malicious traffic as NTP and get through firewalls.
The malware also determines the server's public IP using services including ipify, icanhazip, ident.me, and ipinfo.io, and checks Linux's TracerPid value to detect tracing. If tracing is active, the malware still installs, but does not beacon.
Sansec says an unexpected surge of Magento "Payment Transaction Failed Reminder" emails may indicate exploitation, and also recommends monitoring for 'kworker' or 'fc-cache' processes, suspicious cron entries, and temporary files.
If there is suspicion of compromise, it is recommended to rotate Magento credentials.
At the time of writing, Adobe has not released fixes for StyleSmuggler, but the firm's next scheduled security release is tomorrow, September 8.
Until fixes are made available, Sansec recommends that website administrators disable GraphQL as a mitigation measure.
BleepingComputer has contacted Adobe to ask if a fix for StyleSmuggler is planned for rollout tomorrow, but the company has not yet responded.
The first exploitation incident was recorded on September 4 on a target running the latest security updates.
E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release.
Magento is a popular open-source e-commerce platform by Adobe installed on more than 160,000 websites, including 14,000 of the top 1 million sites.
Linux backdoor
The exploit Sansec observed in the wild abuses Magento's template system through PHP code injection to generate a fake "failed-payment" email, which triggers code execution.
Successful exploitation installs a small Rust-based backdoor as a background process, disguised as [kworker/u:8:0]. Newer versions disguise the process as fc-cache and copy it to ~/.cache/fontconfig/fc-cache.
According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes for persistence.
Although Sansec did not observe any follow-on activity, the malware can communicate with remote infrastructure and receive commands.
The researchers note that earlier samples of the backdoor used TLS/WebSockets to communicate with the command-and-control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP).
They send UDP packets to port 123 and use hostnames that resemble time-syncing infrastructure, helping to mask malicious traffic as NTP and get through firewalls.
The malware also determines the server's public IP using services including ipify, icanhazip, ident.me, and ipinfo.io, and checks Linux's TracerPid value to detect tracing. If tracing is active, the malware still installs, but does not beacon.
Sansec says an unexpected surge of Magento "Payment Transaction Failed Reminder" emails may indicate exploitation, and also recommends monitoring for 'kworker' or 'fc-cache' processes, suspicious cron entries, and temporary files.
If there is suspicion of compromise, it is recommended to rotate Magento credentials.
At the time of writing, Adobe has not released fixes for StyleSmuggler, but the firm's next scheduled security release is tomorrow, September 8.
Until fixes are made available, Sansec recommends that website administrators disable GraphQL as a mitigation measure.
BleepingComputer has contacted Adobe to ask if a fix for StyleSmuggler is planned for rollout tomorrow, but the company has not yet responded.
Mathspace Discloses Data Breach Affecting Over 1 Million People
By Sergiu Gatlan for bleepingcomputer
bleepingcomputer
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.
Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023).
In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians.
"On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected," Savoy said.
"Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login."
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
Savoy noted that only students and school staff from Australia and New Zealand had their data stolen in the incident. Although the attackers didn't steal credentials, academic records and information, in some cases they may have been able to link some impacted accounts to their schools.
"A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected," he added.
"No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we understand this may be possible."
Savoy also warned affected students and school staff that attackers may target them using the stolen data, and advised them to watch for suspicious account-related activity, such as changes to account details and password-reset messages.
Metabase breaches claimed by ShinyHunters
This breach adds to a string of other incidents impacting the Metabase instances of multiple other companies worldwide over the last month,
As BleepingComputer previously reported, threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access.
Trezor revealed on August 13 that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk. On Friday, it warned that the number of affected individuals has risen to 81,000.
Although Trezor has yet to attribute the attack to a specific threat actor or hacking group, BleepingComputer has learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang. ShinyHunters also added Metabase to its dark web leak site on August 11.
The list of affected companies in this campaign also includes laptop maker Framework and online form-building platform Tally, which have also disclosed data breaches after their Metabase instances were hijacked.
Previously, ShinyHunters has been linked to breaches at more than a dozen Snowflake customers, Salesloft Drift and Salesforce Aura campaigns targeting hundreds of Salesforce customers, and over 100 enterprise victims following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.
Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023).
In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians.
"On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected," Savoy said.
"Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login."
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
Savoy noted that only students and school staff from Australia and New Zealand had their data stolen in the incident. Although the attackers didn't steal credentials, academic records and information, in some cases they may have been able to link some impacted accounts to their schools.
"A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected," he added.
"No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we understand this may be possible."
Savoy also warned affected students and school staff that attackers may target them using the stolen data, and advised them to watch for suspicious account-related activity, such as changes to account details and password-reset messages.
Metabase breaches claimed by ShinyHunters
This breach adds to a string of other incidents impacting the Metabase instances of multiple other companies worldwide over the last month,
As BleepingComputer previously reported, threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access.
Trezor revealed on August 13 that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk. On Friday, it warned that the number of affected individuals has risen to 81,000.
Although Trezor has yet to attribute the attack to a specific threat actor or hacking group, BleepingComputer has learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang. ShinyHunters also added Metabase to its dark web leak site on August 11.
The list of affected companies in this campaign also includes laptop maker Framework and online form-building platform Tally, which have also disclosed data breaches after their Metabase instances were hijacked.
Previously, ShinyHunters has been linked to breaches at more than a dozen Snowflake customers, Salesloft Drift and Salesforce Aura campaigns targeting hundreds of Salesforce customers, and over 100 enterprise victims following data-theft attacks that exploited an Oracle PeopleSoft zero-day flaw.
Trezor Data Breach Impact Now Reaches 81,000 Customers
By Sergiu Gatlan for bleepingcomputer
bleepingcomputer
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 US customers.
In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
On Friday, it published an update to confirm that the breach impact has expanded after ShipMonk failed to delete the exposed data from its systems as required by Trezor's contract and data policy.
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details-- name, email, phone number, shipping address, order number-- exposed," Trezor said.
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
The company added that the breach did not affect its operations or services, that its systems were not compromised, and that all Trezor devices are secure.
It also warned affected customers to be wary of any messages requesting personal information, as they may be targeted in phishing attacks.
"Be aware of the increased risk of phishing. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks," Trezor said.
Metabase campaign linked to ShinyHunters extortion gang
While the company has yet to share how ShipMonk's systems were breached, breach notification emails sent to affected customers and seen by BleepingComputer said the attackers exploited a vulnerability in the 3rd-party analytics platform Metabase.
As BleepingComputer previously reported, Metabase revealed that the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance.
BleepingComputer has also learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang.
The list of affected companies in the Metabase campaign includes online form-building platform Tally and laptop maker Framework, which have also notified customers of data breaches after their instances were hijacked.
In January 2024, Trezor disclosed another data breach after threat actors compromised its 3rd-party support ticketing portal and accessed data-- e.g., names, usernames, and email addresses-- from roughly 66,000 users.
This stolen data was later used in phishing attacks attempting to steal recipients' 24-word wallet recovery seeds.
In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
On Friday, it published an update to confirm that the breach impact has expanded after ShipMonk failed to delete the exposed data from its systems as required by Trezor's contract and data policy.
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details-- name, email, phone number, shipping address, order number-- exposed," Trezor said.
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
The company added that the breach did not affect its operations or services, that its systems were not compromised, and that all Trezor devices are secure.
It also warned affected customers to be wary of any messages requesting personal information, as they may be targeted in phishing attacks.
"Be aware of the increased risk of phishing. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks," Trezor said.
Metabase campaign linked to ShinyHunters extortion gang
While the company has yet to share how ShipMonk's systems were breached, breach notification emails sent to affected customers and seen by BleepingComputer said the attackers exploited a vulnerability in the 3rd-party analytics platform Metabase.
As BleepingComputer previously reported, Metabase revealed that the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance.
BleepingComputer has also learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang.
The list of affected companies in the Metabase campaign includes online form-building platform Tally and laptop maker Framework, which have also notified customers of data breaches after their instances were hijacked.
In January 2024, Trezor disclosed another data breach after threat actors compromised its 3rd-party support ticketing portal and accessed data-- e.g., names, usernames, and email addresses-- from roughly 66,000 users.
This stolen data was later used in phishing attacks attempting to steal recipients' 24-word wallet recovery seeds.
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
By Ravie Lakshmanan for The Hacker News
The Hacker News
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.
"The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a technical report published last week.
JSCeal was first documented by Check Point in July 2025, highlighting the threat actors' use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust.
Malvertising campaigns distributing the malware make use of 2 ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components.
As recently as last month, ad security platform Confiant disclosed details of a massive malvertising operation codenamed SourTrade, which has been observed impersonating trusted trading and cryptocurrency brands, such as Solana, Luno, and TradingView, to serve lookalike portals with malicious JavaScript that instructs web browsers to assemble malware directly in memory.
The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America. Evidence indicates that the campaign overlaps with a JSCeal campaign described by Bitdefender in September 2025.
"What makes SourTrade technically distinct is what happens on its landing page," Confiant said. "It does not distribute finished malware. Instead, it delivers assembly instructions to the victim's browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim's machine. No finished malware ever exists on the network."
JSCeal is protected using javascript-obfuscator, with the operators repeatedly using four groups of transformations to obscure the malware. These include:
The Israeli cybersecurity company said it developed a "fully static deobfuscation pipeline" to decode compiled V8 JavaScript bytecode protected with the utility, thereby offering insights into the malware's execution flow and its features, counting its ability to enumerate installed browsers, and query saved secrets, cookies, OAuth tokens, and other data from them, as well as "router" functions that register handlers for the collected information.
"The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a technical report published last week.
JSCeal was first documented by Check Point in July 2025, highlighting the threat actors' use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust.
Malvertising campaigns distributing the malware make use of 2 ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components.
As recently as last month, ad security platform Confiant disclosed details of a massive malvertising operation codenamed SourTrade, which has been observed impersonating trusted trading and cryptocurrency brands, such as Solana, Luno, and TradingView, to serve lookalike portals with malicious JavaScript that instructs web browsers to assemble malware directly in memory.
The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America. Evidence indicates that the campaign overlaps with a JSCeal campaign described by Bitdefender in September 2025.
"What makes SourTrade technically distinct is what happens on its landing page," Confiant said. "It does not distribute finished malware. Instead, it delivers assembly instructions to the victim's browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim's machine. No finished malware ever exists on the network."
JSCeal is protected using javascript-obfuscator, with the operators repeatedly using four groups of transformations to obscure the malware. These include:
- Replacing function and variable names with short or nonsensical identifiers
- Splitting important strings into chunks-- which are subsequently encoded and RC4-protected-- and then reconstructing them through decoder functions
- Using control-flow flattening to turn program flow into a flat, single-level switch statement controlled by an infinite loop and a state variable with the goal of making analysis and reverse‑engineering harder
- Forwarding function calls through proxy helpers and wrapping simple operations, like addition, subtraction, comparison, or function invocation, in dedicated helper functions
The Israeli cybersecurity company said it developed a "fully static deobfuscation pipeline" to decode compiled V8 JavaScript bytecode protected with the utility, thereby offering insights into the malware's execution flow and its features, counting its ability to enumerate installed browsers, and query saved secrets, cookies, OAuth tokens, and other data from them, as well as "router" functions that register handlers for the collected information.
The browser stealing module targets a long list of Chromium-based browsers, such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc. For each browser, the malware navigates to the expected location of its user-data directory and lists available profiles, from where cookies and passwords are extracted.
What's more, JSCeal is equipped to leverage the stolen cookie data to reconstruct a browser session and conduct active session replay attacks to bypass authentication and gain unauthorized access to a victim's Google account. A second module embedded within the malware offers surveillance capabilities by recording keystrokes and taking screenshots.
"A common technique used by banking trojans is to install a local proxy and inject or modify web content in selected services," Check Point said. "JSCeal follows a similar pattern: the recovered code shows proxy setup, certificate generation and installation, and service-specific request and response modification."
"The proxy is not limited to passive interception. The recovered code contains dedicated handlers that modify selected requests and responses for specific services. A configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies."
There also exist multiple handlers specifically focused on cryptocurrency platforms, one of which captures account data and records cryptocurrency balances.
"JSCeal combines two forms of analysis friction: a version-specific compiled V8 format and several layers of JavaScript obfuscation applied before compilation. Neither makes the malware impossible to reverse, but together they move it outside the workflows that analysts normally rely on," security researcher Aleksandra 'Hasherezade' Doniec said.
"Taken together, these developments show that the JSCeal authors are investing both in making the payload harder to analyze and in broadening its platform coverage. With campaigns continuing into recent months, the changes indicate that JSCeal remains under active development."
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH
Without Authentication
By Swati Khandelwal for The Hacker News
The Hacker News
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5.
Successful attacks date to at least September 2. The Hacker News's September 6 review of the warning found no victim count or attacker identity.
MikroTik's security update lists fixed RouterOS releases. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes.
According to the vendor's default firewall explanation, home MikroTik devices block public access to management ports while their default firewall rules remain intact.
The Hacker News checked CERT's affected RouterOS versions against MikroTik's listed fixes on September 6. Use the official RouterOS site for your update.
Successful attacks date to at least September 2. The Hacker News's September 6 review of the warning found no victim count or attacker identity.
MikroTik's security update lists fixed RouterOS releases. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes.
According to the vendor's default firewall explanation, home MikroTik devices block public access to management ports while their default firewall rules remain intact.
The Hacker News checked CERT's affected RouterOS versions against MikroTik's listed fixes on September 6. Use the official RouterOS site for your update.
The 7.23.5 regression fix addresses an IPv6 DHCP-- Dynamic Host Configuration Protocol-- problem introduced in 7.23.4 while retaining the security update.
Until the update can be installed, CERT recommends turning off exposed services or restricting access to trusted management networks, particularly for SSH, WWW/WWW-SSL, and bandwidth-test.
It also advises against initiating Transport Layer Security (TLS) connections or using RouterOS's built-in SSH clients from an unpatched device. These temporary restrictions cover the broader set of vulnerabilities and do not replace the update.
MikroTik's Flagged status guidance states that RouterOS flags a device when startup checks detect suspicious configuration. RouterOS disables those entries and restricts certain functions.
After updating, check the logs and run /system/device-mode/print to inspect that status. Even without a warning, inspect the configuration for unknown users, scripts, and other unrecognized changes.
CERT also points to unexpected highly privileged ops accounts and account-creation logs containing ssh:-2@ as signs to investigate.
If the warning, logs, or configuration suggest compromise, CERT recommends these recovery steps. Do not clear Flagged before preserving the evidence and completing the analysis.
- Isolate the router from the network and preserve its logs and configuration before resetting it. CERT's preservation guide in Polish explains how to export and download the files.
- Restore factory settings and rebuild using a trusted, verified configuration. Do not blindly restore a full backup from the potentially compromised device.
- Change passwords, keys and other secrets in use.
CERT calls the reported 2-flaw combination MikroTrick. The Hacker News compared CERT's warning and vulnerability disclosure on September 6. Neither explicitly identifies which 2 vulnerabilities form the observed chain or explains how they combine to give administrative control.
The 7.25beta3 release notes have a September 2 changelog date, while the beta and other initial fixes were announced on September 3. The Hacker News compared these release announcements with CERT's attack timeline on September 6. Those dates do not establish whether a fix was publicly available before the attacks, so zero-day status remains unverified.
The Hacker News has contacted CERT Polska and MikroTik for comment.
Unpatched Magento and Adobe Commerce Zero-Day Exploited
to Backdoor Online Stores
By Swati Khandelwal for The Hacker News
The Hacker News
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.
Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early because stores are being compromised right now," the company said.
As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update.
A successful attack gives the attacker code execution on the store's server and installs a persistent backdoor. Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9.
Its first victim ran 2.4.6-p15 with Adobe's July and August 2026 security updates applied, which is the latest patch level Adobe offers for that release line and one that Adobe's August bulletin labels 2.4.6-2026-aug.
Sansec has not published a reproduction on Adobe Commerce or on Adobe Commerce on Cloud, and Adobe has not confirmed which versions are affected. Sansec has not said how many stores have been compromised.
The researchers' interim advice for stores not running its Shield product is to temporarily disable GraphQL until Adobe releases a fix.
Disrex Group, a Magento hosting and development company that hosts and responded to 2 of the compromised stores, notes that headless and progressive web app storefronts require GraphQL, whereas most classic and Hyvä storefronts do not.
Adobe's next scheduled security release is on September 8, Sansec said, and it is not yet known whether that release will cover this bug.
Disrex's findings are independent evidence of exploitation from outside Sansec. In an incident-response repository published on September 5, the company said it handled two compromised stores and a third that was attacked but not breached, and that its web-server rules are based on attack traffic captured on one of the compromised stores. In answers to questions from The Hacker News, Disrex said both stores ran Magento Open Source rather than Adobe Commerce, and that it hosts them itself through its hosting brand RexHosting.
The store Disrex labels Store A ran Magento Open Source 2.4.8 and was a Sansec Shield customer, with the module installed, enabled, and licensed. It was hit at 23:10 UTC on September 4, hours before Sansec's first blocking rules for this flaw went live, and Disrex said Shield was active and blocking other malicious traffic against the store at the time.
Store B, which was not a Shield customer, ran Magento 2.4.7-p2, a security patch level that Adobe's version history dates to August 2024, eight levels behind the current 2.4.7-p10. It was first hit at 00:55 UTC on September 5, Disrex said, and it is the store from which the company's web-server rules and its reading of the vulnerable code were taken.
Both stores were breached inside the roughly eight-hour window between the first exploitation Sansec observed and the moment any defence for it existed, Disrex said. "Patch status was irrelevant here, which is the part merchants most need to hear," the company told The Hacker News.
The repository carries its own warning. "This repository was written with AI assistance, during a live incident, in a few hours," its README says, adding that it has not been reviewed, that its Apache rules were never run against a live Apache server, and that most of its cleanup commands were written rather than executed.
Sansec's indicators describe the implant as a background process disguised under [kworker/u:8:0], a name that belongs to a Linux kernel thread, with a binary installed at ~/.local/share/.gvfsd/gvfsd-user under the site user's home directory rather than the web root, and a cron entry that restarts it every five minutes.
Disrex described the binary as a stripped, statically linked Rust program of roughly 1.9 MB built for x86-64 and arm64, and said the cron entry is written straight to the spool file under /var/spool/cron/crontabs/, so the system log shows no crontab replacement.
One store carried the same line 1,728 times, and the implant re-added it within a second of removal.
Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early because stores are being compromised right now," the company said.
As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update.
A successful attack gives the attacker code execution on the store's server and installs a persistent backdoor. Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9.
Its first victim ran 2.4.6-p15 with Adobe's July and August 2026 security updates applied, which is the latest patch level Adobe offers for that release line and one that Adobe's August bulletin labels 2.4.6-2026-aug.
Sansec has not published a reproduction on Adobe Commerce or on Adobe Commerce on Cloud, and Adobe has not confirmed which versions are affected. Sansec has not said how many stores have been compromised.
The researchers' interim advice for stores not running its Shield product is to temporarily disable GraphQL until Adobe releases a fix.
Disrex Group, a Magento hosting and development company that hosts and responded to 2 of the compromised stores, notes that headless and progressive web app storefronts require GraphQL, whereas most classic and Hyvä storefronts do not.
Adobe's next scheduled security release is on September 8, Sansec said, and it is not yet known whether that release will cover this bug.
Disrex's findings are independent evidence of exploitation from outside Sansec. In an incident-response repository published on September 5, the company said it handled two compromised stores and a third that was attacked but not breached, and that its web-server rules are based on attack traffic captured on one of the compromised stores. In answers to questions from The Hacker News, Disrex said both stores ran Magento Open Source rather than Adobe Commerce, and that it hosts them itself through its hosting brand RexHosting.
The store Disrex labels Store A ran Magento Open Source 2.4.8 and was a Sansec Shield customer, with the module installed, enabled, and licensed. It was hit at 23:10 UTC on September 4, hours before Sansec's first blocking rules for this flaw went live, and Disrex said Shield was active and blocking other malicious traffic against the store at the time.
Store B, which was not a Shield customer, ran Magento 2.4.7-p2, a security patch level that Adobe's version history dates to August 2024, eight levels behind the current 2.4.7-p10. It was first hit at 00:55 UTC on September 5, Disrex said, and it is the store from which the company's web-server rules and its reading of the vulnerable code were taken.
Both stores were breached inside the roughly eight-hour window between the first exploitation Sansec observed and the moment any defence for it existed, Disrex said. "Patch status was irrelevant here, which is the part merchants most need to hear," the company told The Hacker News.
The repository carries its own warning. "This repository was written with AI assistance, during a live incident, in a few hours," its README says, adding that it has not been reviewed, that its Apache rules were never run against a live Apache server, and that most of its cleanup commands were written rather than executed.
Sansec's indicators describe the implant as a background process disguised under [kworker/u:8:0], a name that belongs to a Linux kernel thread, with a binary installed at ~/.local/share/.gvfsd/gvfsd-user under the site user's home directory rather than the web root, and a cron entry that restarts it every five minutes.
Disrex described the binary as a stripped, statically linked Rust program of roughly 1.9 MB built for x86-64 and arm64, and said the cron entry is written straight to the spool file under /var/spool/cron/crontabs/, so the system log shows no crontab replacement.
One store carried the same line 1,728 times, and the implant re-added it within a second of removal.
On one of the 2 stores, the implant made no outbound connection at all. It held 28 connections to the store's own Redis instance on port 6379 and read Magento's session storage from it, Disrex said, and neither of its 2 packet captures, each over 200 MB and taken while the implant was live, contained a single packet to the download host or the command-and-control address that Sansec listed.
Disrex told The Hacker News over email that each store ran in its own isolated account with a single site owner, no sudo rights, and no path to any other customer, that the implant ran as the unprivileged site user and could reach nothing beyond that store, and that it confirmed no lateral movement and no other affected site on its platform.
Both stores were contained the same day, roughly eleven and fourteen hours after first contact, the company said, and it found no evidence of data exfiltration, no rogue admin accounts, no injected payment skimmer, and no database backdoor. All sessions were invalidated, and credential rotation is underway as a precaution.
Because it runs a number of Magento stores on its own platform and found the first compromise quickly, Disrex said, it swept its whole estate within the hour and found the second store the same afternoon. The company has also published an incident write-up.
Sansec said that for Shield customers attacked before its rules went live, it has no indication that the backdoor was actually used, and recommended rotating Magento credentials wherever the process has been identified.
The attack works in 2 stages, according to Sansec's outline. It first plants PHP code in a file that Magento itself writes, for example, when generating a failure report. Then it makes Magento execute that file by triggering the platform's standard "Payment Transaction Failed Reminder" email. The code runs while Magento renders the message, so no one has to open it, and the attack can succeed even if email delivery fails.
Sansec has not yet published the full exploit chain and said a breakdown of the chain, the dropper, and the implant will follow in an update.
Disrex's reading of the chain, published in a mechanism write-up alongside its rules, is that a directive within the injected text drives a sequence of Magento's own classes into code that exists solely to serve the command-line dependency-injection compiler.
That code ends by including a file path the attacker chose: the log poisoned a moment earlier. The executed PHP dropper attempts 6 PHP functions in turn to start a process, then downloads and launches the implant. Disrex names 3 files under setup/src/Magento/Setup/Module/Di/Code/ as the point where the chain ends, and told The Hacker News it identified that sink on its own by reading Magento source on the compromised store. Sansec has not confirmed that reading, and Disrex does not publish the assembled request.
Two locations matter for the first stage. Sansec's published check searches var/report/ for the marker X_TRACE_. Disrex said both of its infections were poisoned through var/log/system.log instead and would have been missed by that check, so both directories need searching.
The marker has already drifted: Disrex saw a trigger header of the form X-TRACE- followed by 10 hex characters on the morning of September 5 and the same header without the word TRACE by the afternoon, so a search should match the shape rather than the exact string.
A TypeError from array_merge() with an integer argument in system.log, immediately after the include, is evidence that the exploit succeeded, Disrex said. However, a stealthier variant returns an empty array and leaves nothing in the log.
For the process, Disrex said that a genuine kernel thread is owned by root and has no resident memory, so a bracketed name on the site user with real memory usage is the implant. The implant sets its command line to the literal bracketed string, so a check written against the process's comm field matches nothing.
Disrex also found that the binary running in memory on one store was a different build from the file on disk, and advises hashing the running process from /proc/<pid>/exe as well as the file. Unexpected bursts of "Payment Transaction Failed Reminder" emails are a reason to investigate, Sansec said, although legitimate declined payments generate the same notification.
The following indicators have been published by Sansec and in Disrex's indicator list:
- Process: [kworker/u:8:0] owned by a non-root user
- File: ~/.local/share/.gvfsd/gvfsd-user
- File: ~/.local/share/.gvfsd/.gvfsd_<8hex>.lock
- File: /tmp/.gvfsd_<8hex>.lock
- File: /tmp/.kw_<random><random>
- Cron: */5 * * * * exec <home>/.local/share/.gvfsd/gvfsd-user, with a variant pointing at /tmp/.kw_
- SHA-256: e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7 (Sansec's sample)
- SHA-256: 8334b434fa3fe9f59cebe9609b11e0b1fd19d10212c45c705adec1902a1d06ef (on disk on both Disrex stores)
- SHA-256: 251fabd50d7b18a8b5e1b3ef5d64e7198c17244778f6461fb1ab07f6169bf220 (running in memory on one Disrex store)
- Domain: 247.cdnflare[.]xyz (malware download host)
- IP: 99.84.67[.]186:443 (command-and-control over WebSocket and TLS, per Sansec)
- IP: 88.216.72[.]181 (attacker source, per Sansec)
- IP: 5.181.86[.]133 (attacker source sending in bulk, per Disrex)
Sansec recommends its eComscan scanner to detect the implant, and said version 1.9.7 will terminate the process for Shield customers.
Disrex reported a clean result on Store A. eComscan ran there at 10:00 UTC on September 5, roughly 11 hours after the implant first ran and while 1,728 cron lines were present, and reported the store clean. The cause was scope rather than a scanner fault, Disrex told The Hacker News: the scheduled scan was pointed at the store's document root, and the implant had installed one directory above it, under the account's home directory. Disrex has since widened the scan path and said it would confirm the eComscan build number separately.
There is no vendor fix to install. Until Adobe ships one, the options are Sansec's temporary GraphQL shutdown; 3 unofficial mitigations published by Disrex, ProxiBlue, and Graycore; and two server settings that do not depend on the flaw.
Disrex published nginx and Apache rules that block requests carrying the exploit's parameters in the URL query string. Its own test on a live store showed the limit: the same parameters sent in a POST body reached PHP, as did a JSON body, because nginx and Apache inspect only the query string, Disrex said. Disrex describes the rules as stopping the campaign as it currently runs rather than the vulnerability.
Disrex's main mitigation adds a check to three methods in Magento's dependency-injection code scanners, preventing them from running outside the command line. The hand edit is reverted by every composer install, so Disrex also ships it as a composer-patches source patch that reapplies on deploy and, it says, applies unchanged from 2.4.6 through 2.4.9.
One of the 3 files, ClassesScanner.php, is called over HTTP by at least one 3rd-party module, mageplaza/module-admin-permissions, and guarding it breaks that module's admin screen, so Disrex tells administrators to search their vendor directory before touching it.
The guard was tested on a harness rather than inside a running store, and Disrex says it is not a complete fix on its own. Disrex told The Hacker News the guard is its own work, written during the response, and was not developed with anyone else. A GitHub user, ProxiBlue, separately published the same guard on September 5 as 3 unofficial patches. Neither Sansec nor Adobe has confirmed that these scanners are where the chain ends.
Graycore, LLC published a Magento module on GitHub and Packagist on September 5 whose current code, Graycore says, hardens 3 points on the chain: the email template block directive refuses backend blocks, the grid row URL generator checks a class before building it, and PHP opening tags in Web API fatal error reports are broken.
The version on Packagist at the time of writing was an earlier release whose only mitigation targeted a PayPal GraphQL resolver that has since been removed. The README says "That is hardening, not a fix" and warns that other paths through the vulnerability remain open and that a store may already be compromised.
Two server settings do not depend on knowing the chain at all, Disrex said. At one of its 2 stores, the first 4 of the 6 PHP functions the dropper tried were disabled; proc_open was not, and the dropper used it to start the implant, with open_basedir doing nothing to contain the child process.
Adding proc_open to PHP's disable_functions, and mounting /tmp, /var/tmp and /dev/shm with noexec so a downloaded binary cannot run, are the layers Disrex puts ahead of every rule in its repository.
For a store that is already infected, Disrex's cleanup guide sets the order: preserve evidence first, remove the cron entry before killing the process because the process restores it, do not reboot because the copy under /proc may be the only remaining binary, and do not run composer install to clean up because it overwrites the timestamps that show what was touched.
It then recommends flushing session storage since the implant read it, and rotating the crypt/key in app/etc/env.php, as well as every admin password, every payment provider API key, and every other integration credential in that file.
Hosting providers Nexcess and Liquid Web posted identical incident notices on September 5, stating they were reviewing their server environments and implementing precautionary measures.
Neither claims a confirmed customer compromise or its own reproduction of the flaw. Disrex recorded 26 distinct source addresses across its 2 stores, taken from the stores' own nginx access logs and deduplicated, 2 of them hosting infrastructure sending in bulk and the rest a residential proxy pool sending 2 to 6 requests each, and said that blocking the single attacker address in Sansec's advisory would have stopped less than a quarter of the traffic it saw. An earlier count of 28 included 2 of Disrex's own servers making verification requests during the response, which it removed. No source has named the attackers.
The Hacker News has reached out to Adobe, Sansec, and Graycore for comment, and will update the story if we hear back.
I Rented a Car, and Within Hours, My Driver's License Was for Sale
By Dan Goodin for Ars Technica
The FBI is reportedly investigating a massive data breach that is unfolding in real time.
The FBI is reportedly investigating a massive data breach that is unfolding in real time.
Not long ago, I rented an SUV from a well-known car rental company. Within hours of an employee scanning my driver's license, a high-resolution scan of my ID was available for sale on the dark web.
An exposé published Tuesday by KrebsOnSecurity reports that my license was one of more than 153 million that were available through Nexus, the name of the new ID theft service. Like other driver's licenses available there-- including some belonging to journalist Brian Krebs, his mother, an FBI assistant director, and several security researchers-- my license was purported to include multiple image files showing both the front and back of the ID. Besides a basic image scan, the files also captured the images in the infrared and ultraviolet spectrums. Presumably, the additional formats may allow cloned-based counterfeit IDs to pass hologram tests.
Growing by the day
Besides advertising the availability of driver's licenses, Nexus offered to sell a bevy of other forms of ID. They included:
- Identification cards
- Travel cards
- International DL/ID
- Medical cards
- Common Access Cards
- Residence cards
- Employment authorizations
Krebs said the FBI is investigating.
Some of the records Krebs observed listed their "source" as "CDL," which may be short for "commercial driver's license." Other records identified the source notation as "CAC," which may refer to Common Access Cards, which Krebs said are "government issued identity cards that grant physical access to government buildings and secure rooms." Nexus also claimed to provide scans of marijuana dispensary cards. One of the victims he talked to reported visiting a Las Vegas outlet of Planet13, a multi-state dispensary chain.
The timing of newly available scans-- typically within a day, if not hours, of me and a small sample of other victims presenting them at rental companies or others-- likely means that Nexus has near real-time access to data flowing through the 3rd-party scanning service these businesses are using. Over a span of 24 hours, Krebs said the number of driver's licenses listed as available grew by almost 400,000. That's another indication that the breach has been ongoing and new cards become available shortly after they're harvested.
Using publicly available information, Krebs found that IDScan.net, a New Orleans-based ID scanning service, has announced an exclusive arrangement with Planet13. It also listed Hertz and 11 other companies as using its services. IDScan.net went on to say that its scans capture both infrared and ultraviolet spectra.
Representatives from IDScan didn't immediately answer questions sent by email. An IDScan.net spokesperson told Krebs the company is investigating. My car rental company representatives also didn't immediately answer questions.
The availability of my driver's license to anyone willing to cough up a fee isn't exactly a comforting thought. Yes, my personal details-- including current and former addresses, Social Security number, demographics, and more-- have been breached before, just as they have for millions, if not billions, of others around the world.
This dump is more troubling because of the purported availability of scans in ultraviolet and infrared. Fortunately, Nexus went dark within hours of the KrebsOnSecurity scoop, although that also means there's no way for people to check if their IDs are included. Also somewhat consoling is the ongoing investigation by the FBI.
Google Warns of New Chrome Zero-Day Flaw Exploited in Attacks
By Bill Toulas for bleepingcomputer
bleepingcomputer
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as "Serotav."
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout.
"Google is aware that an exploit for CVE-2026-85046 exists in the wild," the advisory reads.
The company did not disclose any technical or specific exploitation details about the flaw to give users and dependent projects time to apply the fix.
Type confusion flaws cause software to misinterpret one type of object as another, allowing attackers to corrupt memory.
V8 is Chrome's open-source JavaScript and WebAssembly engine, which compiles and executes code used by websites.
Hence, CVE-2026-85046 could potentially be triggered by a specially crafted HTML page containing malicious JavaScript, potentially allowing remote code execution within Chrome's sandboxed renderer process.
The update also addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws in Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia, and a race condition in V8.
CVE-2026-85046 is the sixth actively exploited bug Google has fixed in Chrome since the start of the year. Previous fixes include:
Chrome users are recommended to apply the available update as soon as the rollout reaches them by going to Settings > About Chrome and waiting for the update to download and install.
The exploited security issue, identified as CVE-2026-85046, is described as a type confusion. It was reported to Google by researcher Salvatore Gulizia, known online as "Serotav."
The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS, and 152.0.7977.82 on Linux, as part of a gradual rollout.
"Google is aware that an exploit for CVE-2026-85046 exists in the wild," the advisory reads.
The company did not disclose any technical or specific exploitation details about the flaw to give users and dependent projects time to apply the fix.
Type confusion flaws cause software to misinterpret one type of object as another, allowing attackers to corrupt memory.
V8 is Chrome's open-source JavaScript and WebAssembly engine, which compiles and executes code used by websites.
Hence, CVE-2026-85046 could potentially be triggered by a specially crafted HTML page containing malicious JavaScript, potentially allowing remote code execution within Chrome's sandboxed renderer process.
The update also addresses nine other high-severity vulnerabilities, including use-after-free and out-of-bounds memory flaws in Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, Skia, and a race condition in V8.
CVE-2026-85046 is the sixth actively exploited bug Google has fixed in Chrome since the start of the year. Previous fixes include:
- An out-of-bounds read and write vulnerability in Chrome's V8 JavaScript engine (CVE-2026-11645), exploited in the wild and patched in June.
- An iterator invalidation vulnerability (CVE-2026-2441) in CSSFontFeatureValuesMap, Chrome's implementation of CSS font feature values, fixed in mid-February.
- Two additional Chrome zero-days exploited in March attacks: an out-of-bounds write flaw in the Skia 2D graphics library (CVE-2026-3909) and an inappropriate implementation issue in the V8 JavaScript and WebAssembly engine (CVE-2026-3910).
- A use-after-free vulnerability in Dawn (CVE-2026-5281), the cross-platform implementation of the WebGPU standard used by Chromium, was patched in April.
Chrome users are recommended to apply the available update as soon as the rollout reaches them by going to Settings > About Chrome and waiting for the update to download and install.
After the update process is done, a browser restart is required for the fixes to apply.
A similar action is recommended for users of Chrome-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi, though it may take a couple of extra days for fixes to arrive on those apps.
© vocalbits.com