A roundup of 44 items curated from across the security community.

News

The UN World Food Programme discloses a data breach affecting 600,000 households in Gaza.

Mandiant details UNC3753 using vishing and RMM tools for data extortion against US law firms, with some operators attempting in-person theft.

CISA adds an actively exploited SolarWinds Serv-U vulnerability to the KEV catalog.

More this week (5)

Techniques and Write-ups

A research paper demonstrates an AI worm that reasons its way through networks, steals compute from GPU machines to run its own LLM, and self-replicates across Linux, Windows, and IoT targets.

OSNEXUS QuantaStor through v6.6.1 has an unauthenticated blind SQL injection in the login form. Attackers can recover stored password hashes one character at a time using differing login error responses, with no credentials required.

Volexity details how VerdantBamboo breached an MSP to deploy BRICKSTORM across firewalls, NAS, and cloud storage devices, including a zero-day privilege escalation.

Writing tiny responses into a scratch Cache API cache reveals different metadata residue in normal vs. incognito Chrome, because incognito writes to memory instead of disk.

Verichains chains the nginx Rift and PoolSlip vulnerabilities together into a full remote code execution exploit.

Silent Signal finds an unauthenticated RCE as the system superuser on IBM i Management Central, exploiting a client-controlled verify flag on port 5555.

More this week (20)

Tools and Exploits

Praetorian shims all necessary host APIs to run complete implants with all logic inside a WebAssembly VM, demonstrated with Sliver.

A technique for starving EDR of telemetry by throttling the stream, effectively blinding defenses without killing the agent.

More this week (8)