Security Circus Thread - Post your security news here

The Greatest Shitshow on Earth!

Is there a clever new exploit that some of us may want to get a heads up about sooner than later? Post about it here!

1 Like

Tanstack

An NPM supply chain attack called Tanstack spread like wildfire earlier this week.

Great explanation here:

Copy Fail

The previous thread, which made clear there needs to be a global thread to group them together because it keeps happening

Dirtyfrag

Fragnesia

Nginx Rift

A Vulnerability which can enable Remote Code Execution (RCE) found in Nginx

ssh-keysign-pwn

1 Like

Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised

The payload checks for the Docker socket and, if present, attempts container escape through three sequential methods:

A security researcher with an apparent grudge against Microsoft has in recent days disclosed two more Windows zero-days and released a proof-of-concept exploit against a third vulnerability that Microsoft supposedly patched in 2020.

That makes six flaws researcher “Nightmare Eclipse” has disclosed over the past six weeks, some of which attackers are already actively exploiting, and one that the Cybersecurity and Infrastructure Security Agency (CISA) has included in its catalog of known exploited vulnerabilities (KEV).

https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday

GitHub on Tuesday said it’s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform’s source code and internal organizations for sale on a cybercrime forum.

“While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity,” the Microsoft-owned subsidiary said.

UPDATE

However, GitHub today partially confirmed the advertisement’s claims in a series of posts on the official company account on X. According to the Microsoft-owned company, GitHub yesterday detected and contained the compromise of an employee device, which involved a poisoned VS Code extension. GitHub said it removed the malicious extension version, isolated the endpoint, and began incident response.

“Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far,” the series of posts read. “We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first. We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants. We will publish a fuller report once the investigation is complete.”

https://www.darkreading.com/application-security/github-confirms-breach-4k-internal-repos-stolen

1 Like

The bulletin covers multiple NVIDIA GPU Display Driver vulnerabilities. For Windows GeForce users, NVIDIA lists issues in the kernel-mode driver and driver resource handling, including improper GPU resource access, a time-of-check/time-of-use issue and a driver-lock leak. Successful exploitation could allow denial of service, privilege escalation, information disclosure, data tampering or code execution, depending on the CVE. NVIDIA rates the highest Windows/Linux driver issues as “High,” with CVSS scores up to 7.8, while the fixed GeForce Windows R595 driver is 596.36 or newer.

https://videocardz.com/newz/nvidia-tells-users-to-update-gpu-drivers-after-security-disclosure

1 Like

Sunshine has a critical security update

1 Like

“TrapDoor”

TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io

Presumably this is what is effecting some Redhat stuff

1 Like

https://forum.level1techs.com/t/news-story-dump-thread-stories-only/136458/7158?u=daemond

1 Like

Accidentally posted this in the other thread

1 Like

This is curious.

AdGuard Home, when started with the --glinet flag, contains an authentication bypass that allows an unauthenticated attacker to supply a path traversal sequence in the Admin-Token cookie or header. The flaw arises from unsanitized string concatenation used when constructing the token file path within the authglinet middleware, enabling the attacker to redirect file reads to arbitrary paths. This vulnerability can lead to full administrative control over the application without the need to supply valid credentials

2 Likes
1 Like

Anthropic’s Mythos AI reportedly cracked NSA classified systems in hours, that would explain the ban

2 Likes

TLOU-inspired name?

what the actual f#*k

2 Likes