Application Security

Application Security
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
Application Security
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
Application Security
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.
Application Security
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Application Security
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.
Application Security
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Application Security
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
Application Security
AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations
A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE backdoors.
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
Application Security
Copilot for Word Copy-Paste Attack Still Exploitable
Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite mitigations.