Endpoint Security

Cybersecurity
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Cybersecurity
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer than expected.
Application Security
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Application Security
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Application Security
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Application Security
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
Application Security
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Application Security
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.
Application Security
BigBear Phishing Service Bypassed MFA at 258 Organizations
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.
Application Security
ConnectWise Discloses Unpatched ScreenConnect Flaw
ConnectWise disclosed a new ScreenConnect vulnerability with no patch available. The vendor shared temporary mitigations and plans a fix this week.