Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE Do Son
    An ASUS Control Center vulnerability, CVE-2026-75754 (CVSS 10), gives unauthenticated attackers a root shell. Update to v3.1.0.9 now. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout The post CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE appeared first on Daily CyberSecurity.
     

Hacking Public Wi-Fi DNS to Steal Credentials

17 de Agosto de 2026, 08:18

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

  • ✇Firewall Daily – The Cyber Express
  • ZTNA Emerges as VPN Security Risks Put Federal Networks on Alert Samiksha Jain
    Federal agencies are facing growing pressure to evaluate ZTNA as an alternative to traditional VPN architectures, as cybersecurity threats expose weaknesses in internet-facing remote access systems. While VPNs provide encrypted connections for remote users, ZTNA follows a zero-trust model that continuously verifies users, devices, and access requests rather than assuming that authenticated users should receive broad network access. The shift reflects a broader move away from the traditional "
     

ZTNA Emerges as VPN Security Risks Put Federal Networks on Alert

ZTNA

Federal agencies are facing growing pressure to evaluate ZTNA as an alternative to traditional VPN architectures, as cybersecurity threats expose weaknesses in internet-facing remote access systems. While VPNs provide encrypted connections for remote users, ZTNA follows a zero-trust model that continuously verifies users, devices, and access requests rather than assuming that authenticated users should receive broad network access. The shift reflects a broader move away from the traditional "castle-and-moat" security model, where users inside an organization's network are generally trusted while those outside must first pass through a security perimeter. As organizations adopted cloud services, mobile workforces, and geographically distributed infrastructure, this model became more difficult to maintain.

VPN Security Risks Drive ZTNA Considerations

A traditional VPN creates an encrypted connection between a remote user's device and an organization's internal network. The VPN appliance typically sits at the edge of the network and remains accessible from the public internet, where it authenticates users before granting access. This architecture creates several security concerns. VPN appliances must maintain publicly accessible listening ports, making them discoverable and scannable by attackers. If vulnerabilities remain unpatched, those weaknesses can potentially be exploited remotely. The memorandum also points to risks involving legacy code bases, key-exchange processes, and lateral movement. Attackers who obtain legitimate VPN credentials, exploit a vulnerability, or hijack an active session may gain broad access to the internal network. Unlike application-specific access, traditional VPN access operates at the network layer, potentially allowing an authenticated user to reach multiple permitted subnets. Recent incidents involving vulnerable VPN appliances have further highlighted these concerns. The memorandum cites CISA directives addressing exploitation involving Pulse Connect Secure, VMware, and Ivanti Connect Secure products.

How ZTNA Changes Remote Access

ZTNA uses a "never trust, always verify" approach. Instead of treating users inside a network as inherently trusted, the architecture evaluates access requests based on factors such as identity, device health, user role, location, behavior, and risk. The architecture is built around three core components: the Policy Engine, which makes access decisions; the Policy Administrator, which establishes or ends sessions; and the Policy Enforcement Point, which enables, monitors, and terminates connections. Modern ZTNA deployments can also use outbound-only connections, removing the need for publicly accessible inbound listening ports. Rather than placing a user directly onto a corporate network, ZTNA can create an encrypted, application-specific micro-tunnel that limits the user to an authorized resource. Continuous verification is another key difference. Access is not necessarily granted once and maintained for the entire session. Instead, policies can reassess access based on changing security and contextual signals.

ZTNA Also Brings New Security Risks

The shift to ZTNA does not eliminate cybersecurity risks. The memorandum identifies the control plane as a significant concern because it is responsible for authentication, device verification, policy enforcement, and connection management. If an attacker compromises a ZTNA provider or components such as the Policy Engine or Policy Administrator, access decisions could potentially be manipulated. This could result in unauthorized access or prevent legitimate users from reaching resources. Additional security controls, including cryptographic signing of device nodes, may help reduce the impact of a compromised ZTNA provider. The memorandum cites Tailscale Tailnet Lock as an example of this approach.

Federal Agencies Face a Complex Transition

For federal agencies, moving from VPN to ZTNA involves more than replacing one remote-access technology with another. Agencies must consider federal cybersecurity policies, budgets, legacy infrastructure, authentication requirements, and cryptographic standards. NIST Special Publication 800-207 established foundational principles for Zero Trust Architecture, while Executive Order 14028 directed federal agencies toward zero trust, multifactor authentication, and secure cloud services. OMB Memorandum M-22-09 later established a federal zero-trust strategy centered on identity, devices, networks, applications and workloads, and data. A transition could involve assessing existing VPN deployments, identifying applications and user groups, deploying ZTNA alongside VPN infrastructure, and progressively migrating applications. VPN infrastructure could then be decommissioned after applications and users are migrated and validated. However, agencies must also account for recurring ZTNA subscription costs, legacy systems that may not support modern authentication, post-quantum cryptography requirements, NIST standards, FIPS requirements, and FedRAMP approval for cloud-based services. The transition from VPN to ZTNA therefore represents a broader change in how organizations approach remote access. While ZTNA can reduce exposure associated with publicly accessible network perimeters and broad network-level access, agencies must evaluate the technology's own control-plane risks, compliance requirements, costs, and technical limitations before making the shift.
  • ✇Malwarebytes
  • Fake Netflix, Coca-Cola, and FIFA job scams target marketers
    Attackers are impersonating major companies and recruiters to target marketing professionals, using trusted services and browser tricks to make the scam look legitimate. A BleepingComputer article detailing the campaign found at least 34 domains impersonating high-value companies, including Netflix, Coca-Cola, Adidas, and FIFA. The lure is a fake job interview or scheduling request from a “recruiter” representing one of these major companies. The impersonating website then shows the victim
     

Fake Netflix, Coca-Cola, and FIFA job scams target marketers

7 de Julho de 2026, 10:43

Attackers are impersonating major companies and recruiters to target marketing professionals, using trusted services and browser tricks to make the scam look legitimate.

A BleepingComputer article detailing the campaign found at least 34 domains impersonating high-value companies, including Netflix, Coca-Cola, Adidas, and FIFA.

The lure is a fake job interview or scheduling request from a “recruiter” representing one of these major companies. The impersonating website then shows the victim a fake Google sign-in pop-up built inside the page, rather than a real browser window.

Example of sign-in window

To avoid detection, the attackers route victims through a chain of legitimate services before they reach the phishing site. So, instead of going straight from A to D, you go A → B → C → D. In phishing, attackers use this to make the final malicious site look less suspicious, because the victim passes through legitimate-looking services first.

“The operation is abusing the legitimate cloud-based PeopleForce human resources platform and a domain associated with the Salesforce Marketing Cloud service before redirecting the recipient to a malicious landing page.”

BleepingComputer noted that the campaign has been running for at least five months and primarily targets people in marketing roles. We know from our own investigations that job-themed phishing is extremely common and is likely especially effective while entry-level positions remain highly competitive and AI continues to shape the job market.

How to stay safe

Campaigns like these show how AI-enabled scams reshape scams, identity theft, and the ways attackers exploit trust.

As Stefan Dasic wrote in a post about a similar campaign that phished for Facebook credentials:

“The best protection isn’t spotting the fake—it’s knowing that no legitimate hiring process will ever require you to authenticate through an unfamiliar page, whether it’s dressed up as Google, Facebook, or anything else. When in doubt, close the tab, go to the company’s website yourself, and apply the old-fashioned way.”

Other useful tips include:

  • Don’t click links or open attachments in unsolicited job offers.
  • Use a password manager. It won’t autofill your Google username and password on a fake website.
  • Use an up-to-date, real-time anti-malware solution with web protection.

Pro tip: Malwarebytes Scam Guard would have helped identify this attack as a scam.


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

  • ✇Firewall Daily – The Cyber Express
  • Operation Endgame Disrupts SocGholish, StealC Malware Networks Samiksha Jain
    Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware. Led by Europol and
     

Operation Endgame Disrupts SocGholish, StealC Malware Networks

Operation Endgame Disrupts SocGholish

Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware.

Led by Europol and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch ransomware attacks, financial fraud, and attacks against critical infrastructure.

Operation Endgame Targets Cybercrime Infrastructure

During the coordinated action, authorities targeted the infrastructure supporting malware delivery rather than focusing on a single malware family.

Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting malware distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.

According to Europol, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.

[caption id="attachment_112936" align="aligncenter" width="600"]Operation Endgame Image Soure: Europol[/caption] [caption id="attachment_112937" align="aligncenter" width="600"]Operation Endgame Strikes Malware Image Source: Europol[/caption]

SocGholish, Amadey and StealC Malware Played Different Roles

The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.

  • SocGholish functioned as a malware loader that distributed fake browser updates through compromised WordPress websites. Users who installed these fake updates unknowingly infected their systems, allowing attackers to gain initial access and later deploy ransomware or other malicious tools.
  • StealC malware primarily targeted sensitive information stored on infected devices, including passwords, authentication data, and digital identities. The stolen information was later used for fraud or traded within cybercriminal marketplaces.
  • Amadey was mainly distributed through phishing campaigns. It provided attackers with initial access to compromised systems while also offering information-stealing capabilities that enabled the theft of sensitive user data.

Microsoft reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.

Thousands of Infected WordPress Sites Cleaned

One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.

Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish botnet by taking control of domains and shutting down supporting servers.

Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.

The Dutch Police urged WordPress administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.

SocGholish Linked to Evil Corp

Authorities said SocGholish has been linked to Evil Corp, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.

Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.

Europol Coordinates Global Cyber Operation

Europol's European Cybercrime Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.

The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.

Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.
  • ✇Security Affairs
  • 24 Billion Stolen Credentials Exposed in Massive Data Leak Pierluigi Paganini
    24 Billion Records Left Open Online: Passwords, Emails, and Everything Else Exposed database with 24 Billion records revealed stolen credentials from infostealers, Telegram channels, and breach collections, risking account takeovers. Cybernews researchers found an exposed Elasticsearch cluster on June 12th containing 24 billion records and more than 8.3 terabytes of data. They triple-checked the numbers. The numbers held up. “The vast majority of the 24 billion exposed records, our res
     

24 Billion Stolen Credentials Exposed in Massive Data Leak

19 de Junho de 2026, 02:09

24 Billion Records Left Open Online: Passwords, Emails, and Everything Else

Exposed database with 24 Billion records revealed stolen credentials from infostealers, Telegram channels, and breach collections, risking account takeovers.

Cybernews researchers found an exposed Elasticsearch cluster on June 12th containing 24 billion records and more than 8.3 terabytes of data. They triple-checked the numbers. The numbers held up.

“The vast majority of the 24 billion exposed records, our researchers believe, were infostealer logs. In other words, stolen usernames, passwords, and services that these credentials were supposed to grant access to.” reads the report published by Cybernews. “The credential data leak is dangerous simply because of its enormous size. Since the data leaked online, billions of affected accounts are at serious risk of takeovers, especially if they are not protected with multi-factor authentication,” the team explained.”

The vast majority of records were infostealer logs: usernames, email addresses, and plaintext passwords, each credential saved separately alongside the URL it was supposed to unlock. Twenty-four billion is not a typo.

The data came from 36 distinct sources. Over 1.7 billion records traced back to Telegram channels, most of them openly involved in cybercrime and trading stolen credentials. More than 30 of the 36 sources were Telegram channels, with records ranging from a few thousand to hundreds of millions each, written in English and Russian.

The biggest chunk, 22.6 billion records, came from what the owner labeled “collections.” That term is deliberately vague.

“A staggering 22.6 billion records supposedly came from what the data owner named “collections.” These records could come from various infostealer collections previously leaked online, or they may indicate that the records are grouped by the services they are supposed to provide unauthorized access to.” continues the report. “Since the data was taken out of public view soon after the discovery, our researchers could not further investigate the origin of the information within the so-called “collection” source.”

24 Billion

Because the database was taken offline shortly after discovery, researchers couldn’t dig further into what’s actually inside those collections.

Interestingly, nearly 260 million records came from Telegram channels with “Darkside” in the name — yes, the same Darkside ransomware group that knocked out the Colonial Pipeline. Another 150 million records came from a source labeled “local database dumps,” which typically means someone downloaded the contents of a live server. Another 146 million came from a “breach compilation combo,” which is exactly what it sounds like: old breach data repackaged because people reuse passwords and rarely change them.

The researchers also found something unusual mixed in: around 17,000 records containing CVE vulnerability IDs with GitHub links, over 5,200 logs of news articles about recent data breaches, and nearly 2,900 logs of social media posts about cybersecurity incidents. One news article in the dataset was published as recently as February 2026.

“One of the vulnerabilities identified in the exposed cluster involved a Valhall GPU Kernel Driver issue.” states Cybernews. “All of this points to the data owner actively monitoring the cybersecurity landscape, with a likely intent to update their vast collection of credentials with records from the latest data breaches and data leaks.”

Someone isn’t just hoarding old data; they’re keeping it current.

The researchers can’t say how many records are duplicates, how old most of the data is, or who owns the database. They also can’t confirm exactly how many people are affected. What they can say is that the database is no longer publicly accessible, which doesn’t help anyone whose password was already in there. If you reuse passwords and don’t have two-factor authentication turned on, that’s the problem worth fixing today.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, 24 Billion data leak)

  • ✇ASEC BLOG
  • May 2026 Dark Web Issue Trend Report ATCP
    Notes the May 2026 Dark Web Issue Trend Report summarizes the Major Issues that occurred on the deep web and dark web. it stated that due to the nature of the sources, some of the information cannot be fully verified for factual accuracy. Major Issues Hasan’s BreachForums experienced a moderator split, with HasanBroker being ousted […]
     

May 2026 Dark Web Issue Trend Report

Por:ATCP
8 de Junho de 2026, 12:00
Notes the May 2026 Dark Web Issue Trend Report summarizes the Major Issues that occurred on the deep web and dark web. it stated that due to the nature of the sources, some of the information cannot be fully verified for factual accuracy. Major Issues Hasan’s BreachForums experienced a moderator split, with HasanBroker being ousted […]

Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

11 de Maio de 2026, 19:00

Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders.

The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42.

FBI, Indonesian Authorities Team to Take Down Site Ripping Off Users for Millions 

27 de Abril de 2026, 05:36

Phishing still hooks users around the world and coaxes them to hand over credentials. But on occasion the good guys take them down, like the FBI in collaboration with Indonesian law enforcement did with W3LLStore marketplace. 

The post FBI, Indonesian Authorities Team to Take Down Site Ripping Off Users for Millions  appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Banning Routers Won’t Secure the Internet Alan Shimel
    Washington’s push to ban foreign-made Wi-Fi routers may sound tough on cybersecurity, but like earlier bans on foreign drones and telecom gear it risks becoming security theater that ignores the real problem: Millions of unpatched devices already sitting on American networks. The post Banning Routers Won’t Secure the Internet appeared first on Security Boulevard.
     

Banning Routers Won’t Secure the Internet

6 de Abril de 2026, 06:53

Washington’s push to ban foreign-made Wi-Fi routers may sound tough on cybersecurity, but like earlier bans on foreign drones and telecom gear it risks becoming security theater that ignores the real problem: Millions of unpatched devices already sitting on American networks.

The post Banning Routers Won’t Secure the Internet appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Dormant Accounts Leave Manufacturing Orgs Open to Attack  Teri Robinson
    While companies use "perp walks" for terminated employees, 48% of manufacturers fail to revoke digital access within 24 hours. Explore the growing risk of dormant accounts, the 74% automation gap in provisioning, and why experts like Darren Guccione and James Maude call overprivileged identities a "frictionless path" for modern cyberattacks. The post Dormant Accounts Leave Manufacturing Orgs Open to Attack  appeared first on Security Boulevard.
     
  • ✇Security Boulevard
  • How to Setup Credentials for Windows to Use DigiCert KeyLocker & SMCTL? Janki Mehta
    Before you can securely sign software or automate code signing in your Windows environment, you will need to configure your credentials for DigiCert® KeyLocker and the Signing Manager Command-Line Tool (SMCTL). Your credentials create a trusted connection between your local signing tools and DigiCert ONE to ensure that only authorized users are able to access… Read More How to Setup Credentials for Windows to Use DigiCert KeyLocker & SMCTL? The post How to Setup Credentials for Windows to Us
     

How to Setup Credentials for Windows to Use DigiCert KeyLocker & SMCTL?

24 de Fevereiro de 2026, 06:40

Before you can securely sign software or automate code signing in your Windows environment, you will need to configure your credentials for DigiCert® KeyLocker and the Signing Manager Command-Line Tool (SMCTL). Your credentials create a trusted connection between your local signing tools and DigiCert ONE to ensure that only authorized users are able to access… Read More How to Setup Credentials for Windows to Use DigiCert KeyLocker & SMCTL?

The post How to Setup Credentials for Windows to Use DigiCert KeyLocker & SMCTL? appeared first on SignMyCode - Resources.

The post How to Setup Credentials for Windows to Use DigiCert KeyLocker & SMCTL? appeared first on Security Boulevard.

❌
❌