Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • CVE-2026-53365: VsockDrop PoC Enables Unprivileged Local Privilege Escalation Do Son
    A public PoC named VsockDrop turns CVE-2026-53365 into unprivileged local privilege escalation to root on Linux. Details and exploit code are disclosed. Related Posts: Public PoC for CVE-2026-52923 Allows Attackers to Escalate to Root Privilege CVE-2026-77136: TYPO3 Powermail RCE Flaw Exploited in the Wild Weidmueller Router Flaw CVE-2026-63586 With CVSS 9.8 Allows Attackers To Execute Arbitrary Commands With Root Privileges The post CVE-2026-53365: VsockDrop PoC Enables Unprivileged Local Pr
     

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

21 de Agosto de 2026, 20:00

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls

The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

  • ✇Cybersecurity News
  • Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public Do Son
    A zero-click flaw in Xiaomi ShareMe (MiDrop) lets nearby attackers write files silently. Full details and PoC code are now public. Related Posts: CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs The post Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • ChainDrop npm Worm Hits 400+ Packages via Blockchain C2 Do Son
    ChainDrop npm worm infected 400+ packages, stealing cloud keys and CI secrets via blockchain C2. Unit 42 details the full attack chain and fixes. Related Posts: Fake Zoom Installer Drops Overlord RAT on macOS macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate Fake AI Tools Malware Targets Developers Through GitHub The post ChainDrop npm Worm Hits 400+ Packages via Blockchain C2 appeared first on Daily CyberSecurity.
     
  • ✇Unit 42
  • ChainDrop: Inside a Self-Propagating npm Worm Unit 42
    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
     

ChainDrop: Inside a Self-Propagating npm Worm

6 de Agosto de 2026, 19:26

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.

The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

  • ✇Malwarebytes
  • Californians can tell data brokers to DROP their information
    California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place. DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry. Data brokers collect and sell extensive personal information, including financial details, onlin
     

Californians can tell data brokers to DROP their information

3 de Agosto de 2026, 17:50

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place.

DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry.

Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency.

DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency. Starting August 1, 2026, registered data brokers in California are required to access DROP and have 90 days to delete a person’s records after a request.

How to use DROP

You’ll need to provide at least one reachable email address and/or mobile phone to verify your identity and track the request. Be ready to provide basic personal data (name, address, contact details) that brokers are likely to have and that DROP uses to match your records.

  • Go to the DROP portal.
  • Use the “Get Started” button on the homepage.
  • Accept the terms and conditions presented by the platform by using the “I accept” button.
  • You’ll need to verify that you are a California resident: you can either input your personal information manually, or authenticate via Login.gov, which allows identity verification through a federal login. If you receive the message “Unable to verify” your status as a California resident, click the link on screen to “Request a review of your eligibility.”
  • After residency verification, create a deletion request:
    • Provide your email address and/or phone number to verify contact details.
    • Fill in basic information (name, address, etc.) so brokers can locate your records.
  • Submit your request through DROP and you’ll receive a DROP ID that lets you track the status of your request online. Store that number somewhere.

Now, it’s up to the data brokers. They now have 90 days to delete your records and comply with opt‑out obligations. If you run into a problem there is a dedicated help site.

For non-Californians

Some other states—like Oregon, Texas, and Vermont—also require data broker registration, though only California currently offers a centralized platform like DROP. If you live in such a state, check your attorney general’s website or privacy office for a “data broker registry” or opt‑out guidance, and follow their listed processes to submit requests directly to each broker.

Even without DROP, US residents can still reduce data broker collection and sale of their data, but it requires more manual work. Where no centralized government tool exists, you can identify brokers by searching for “data broker opt‑out” and review lists from privacy advocacy groups.

For each broker you’ll have to submit individual requests:

  • Use their web forms, email addresses, or postal addresses to request:
    • Deletion of your data, and
    • Opt‑out from sale or sharing of your data.

You’ll need to provide enough information to match your record (e.g., name, address, email, phone) but avoid oversharing additional sensitive data.

It’s advisable to maintain a spreadsheet with dates, brokers, and confirmations. Most privacy laws specify response deadlines, often 30–45 days, though this varies by state.

Sounds like a lot of work? Malwarebytes Personal Data Remover can help.

How to reduce future data broker collection

This is probably the only field where “security by obscurity” works.

Use multiple email addresses where you reserve one for financial/critical accounts and use aliases or disposable emails for newsletters, shopping, and registrations, making it harder for brokers to build a unified profile.

A VPN encrypts your traffic and hides your IP address, reducing the ability of websites and analytics firms to link activity to a stable, location‑based identifier.

For non‑critical services, avoid providing full legal names, exact home addresses, or phone numbers if they’re not strictly necessary. This is especially true for rewards and loyalty programs.


Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

  • ✇ASEC BLOG
  • June 2026 Threat Trend Report on APT Groups ATCP
    Purpose and Scope The June 2026 Threat Trend Report on APT Groups summarizes the trend of state-sponsored threat groups actively incorporating generative AI, cloud services, OAuth tokens, and commercial MaaS (Malware-as-a-Service) platforms into their attack operations. A key finding is that the scope of attacks has expanded beyond traditional Malware infections to include account and […]
     

June 2026 Threat Trend Report on APT Groups

Por:ATCP
13 de Julho de 2026, 12:00
Purpose and Scope The June 2026 Threat Trend Report on APT Groups summarizes the trend of state-sponsored threat groups actively incorporating generative AI, cloud services, OAuth tokens, and commercial MaaS (Malware-as-a-Service) platforms into their attack operations. A key finding is that the scope of attacks has expanded beyond traditional Malware infections to include account and […]
  • ✇Security Affairs
  • Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools Pierluigi Paganini
    Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulnerabilities patched were found using AI tools, including Anthropic’s Claude and OpenAI’s Codex Security. That’s not a small detail. It changes who’s doing the hunting on the defensive side. The comp
     

Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools

30 de Junho de 2026, 08:32

Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex

Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulnerabilities patched were found using AI tools, including Anthropic’s Claude and OpenAI’s Codex Security. That’s not a small detail. It changes who’s doing the hunting on the defensive side.

The company addressed four bugs in WebKit, the engine that powers Safari and anything else on Apple devices that renders web content.

Below are the descriptions of the vulnerabilities:

  • CVE-2026-43707 – A memory corruption vulnerability in WebKit that can cause an unexpected process crash when handling specially crafted web content.
  • CVE-2026-43716 – A WebKit vulnerability that can trigger an unexpected Safari crash when processing maliciously crafted web content.
  • CVE-2026-43745 – An out-of-bounds write flaw in WebKit that can cause Safari to crash when a user visits specially crafted web content.
  • CVE-2026-43715 – A use-after-free vulnerability in WebKit that can lead to memory corruption when processing maliciously crafted web content.

They’re part of a much bigger patch load. Apple’s advisory lists close to 30 fixes across WebKit alone, including a use-after-free in WebKit Canvas and a flaw that let a malicious website pull restricted content out of the browser sandbox. On the kernel side, three separate bugs could have let a malicious app leak kernel state, crash the system outright, or corrupt kernel memory. Security researcher Hyunwoo Kim, known for finding the Dirty Frag exploit, gets credit for two of those kernel issues.

The updates are live now: iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2. Apple says none of the patched vulnerabilities show signs of having been exploited before the fix shipped. Update anyway, obviously, that’s not really optional advice anymore.

Why the timing matters more than usual? Here’s the part that’s actually new. Apple told Reuters it’s pushing these fixes out ahead of schedule, separate from the next full iOS release, because of how fast AI can now turn a known flaw into a working exploit. As one wire report put it,

“Unless security experts discover ​a hacking campaign targeting a previously unknown software flaw, Apple usually releases security ‌updates ⁠as part of a move from one version of iOS to the next, for example from the currently available version – 26.5 – to the next planned update, 26.6. In the interim, developers and ​other testers trial ​the next ⁠update to iron out any kinks.” states Reuters. “The company said that, instead, the latest round of security updates ​were being made available to everyone ahead of ​the ⁠wider release of 26.6. It said that while there was no evidence that any of the newly patched vulnerabilities had been taken ⁠advantage of, ​the time between the point when ​security fixes were first announced and when they were deployed to customers’ phones ​needed to be compressed.”

That’s a real departure from how Apple normally operates. The company typically bundles security fixes into the next big iOS version bump rather than shipping standalone patches. Reuters described this as “a notable change in Apple’s longstanding practice of packaging security fixes with broader software releases”, which tells you Apple sees the AI-acceleration problem as structural, not a one-off.

The Hacker News confirms that the patches address “flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools.” Same tools that can find these bugs for defenders can, in different hands, help find them for attackers. The race just got faster on both sides.

The irony is hard to miss. AI helped researchers find these flaws, but it’s also making it easier for attackers to discover and exploit bugs more quickly. That’s why Apple is moving faster to release security updates and reduce the time attackers have to take advantage of them.

If you’ve been delaying your updates, now is a good time to install them. While most of these flaws mainly cause crashes, attackers can often combine them with other vulnerabilities to carry out more serious attacks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Apple)

❌
❌