This website uses cookies

Read our Privacy policy and Terms of use for more information.

Patch Tuesday came early this week, and the list of things actively under attack right now is long. Zimbra's SNMP flaw, Windows IKE Extension, macOS Screen Sharing, Microsoft Entra ID, TrueConf, MLflow — all confirmed exploited, all with fixes already out. If you're behind on any of these, you're not behind on theory, you're behind on stuff attackers are using today.

The bigger thread is how much damage comes from things that were never "vulnerabilities" in the traditional sense. Truffle Security found over 9,300 live AWS keys sitting exposed in code and containers, hundreds with full admin rights. A phishing kit called iAuthFlow quietly plants a passkey in your Google account so a password reset doesn't save you. A bandwidth-sharing app turns employee laptops into someone else's proxy network. None of that needed a zero-day. It just needed people to trust the wrong thing.

Mac users get hit from three directions at once — the Screen Sharing bug, a fake CAPTCHA backdoor, and a new stealer called AmnesiaStealer that hijacks live browser sessions instead of just grabbing passwords. Add a Rust supply chain compromise tied to North Korea and a fresh CareCloud breach notice to 3.7 million patients, and the pattern holds: attackers are going after identity and trust, not just code.

Truffle Security found more than 9,300 exposed AWS access keys that remain active, including 817 tied to companies and 526 root keys, with 242 linked to IAM users holding full AdministratorAccess. The four-year study scanned 431,875 AWS secrets across code repos, Docker images, and CI logs, and identified Hugging Face as the largest single leak source with 8,482 exposed keys, many years old and never rotated.

Apple patched an authentication-bypass flaw in macOS Screen Sharing, tracked as CVE-2026-65400, on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The Dutch NCSC says attackers have exploited the bug in the wild, connecting to exposed systems on port 5900 without credentials, gaining root access, and installing Monero cryptominers. Mac users should install the update or disable Screen Sharing and Remote Management if the patch can't be applied immediately.

Microsoft has confirmed that CVE-2026-69836, a critical deserialization flaw in Entra ID rated maximum severity, was exploited in the wild before disclosure on August 20, 2026. The bug allowed unauthenticated remote code execution on backend systems underpinning sign-in for Microsoft 365, Azure, and third-party apps; Microsoft has already patched its infrastructure server-side, so no customer action is required, though the company recommends reviewing sign-in logs and access policies for signs of prior compromise. Researcher Robert Fitzpatrick was credited with reporting the issue.

A fake CAPTCHA campaign identified by NetbyteSEC in July 2026 tricks Mac users into pasting and running a Terminal command that installs a persistent backdoor, steals passwords, browser and wallet data, and deploys XMRig to mine Monero. The malware uses a Cloudflare Worker and a Polygon smart contract (EtherHiding) to hide its command-and-control address, and shows a fake macOS password prompt to harvest credentials. Researchers recommend treating any CAPTCHA that asks users to open Terminal as malicious and disconnecting affected Macs immediately.

A new macOS infostealer called AmnesiaStealer, written in Rust, gives attackers interactive remote access to a victim's already logged-in Chromium browser sessions rather than just stealing stored credentials. The malware spreads through a ClickFix social-engineering campaign using fake GitHub download pages that trick users into running malicious commands instead of installing the software they expect.

A new ClickFix campaign targeting macOS users is hiding its command-and-control infrastructure inside Polygon smart contracts, a technique known as EtherHiding, to deploy an Atomic macOS Stealer (AMOS) variant, a persistent backdoor, and an XMRig cryptominer. The attack starts with fake CAPTCHA prompts that trick victims into running malicious commands, and using blockchain-based C2 makes the infrastructure far harder to take down than traditional hardcoded servers.

A new phishing toolkit called iAuthFlow v2, selling for more than $10,000 on Russian dark web forums, lets attackers maintain access to compromised Google, Microsoft, iCloud, or LinkedIn accounts by secretly registering their own passkey seconds after stealing login credentials. Researchers at Abnormal found the tool generates the rogue passkey within about six seconds of a successful phishing login, meaning a password reset alone won't lock attackers out. Abnormal recommends auditing accounts for unauthorized passkeys, OAuth grants, mail rules, and revoking any attacker-enrolled authentication methods.

Cisco patched nine critical vulnerabilities across its Crosswork and Secure Workload platforms, six of them rated a maximum CVSS score of 10.0, including SQL injection, missing authentication, and improper access control flaws. Crosswork issues affect version 7.2.1 and earlier, fixed in 7.2.1-SP, while Secure Workload flaws hit the 3.10 and 4.0 branches, patched in 3.10.9.1 and 4.0.4.16. Cisco found all nine internally, partly using AI-assisted testing, and says none are known to be exploited.

Researchers at Silent Push found that Peer2Profit, a bandwidth-sharing app active since 2021, feeds enrolled Android and macOS devices into Astroproxy's residential, mobile, and datacenter proxy pools, exposing 117,224 unique IPs over a 72-hour test period. Employees who install the app on corporate or office-connected devices risk having their IP address linked to fraud, scanning, or credential-stuffing traffic run by paying proxy customers. Researchers also bypassed Astroproxy's block on private IP ranges using DNS resolution, reaching an internal router's management interface, a flaw reported before publication that remains unfixed.

Microsoft issued 22 security updates Thursday covering critical and high-severity flaws in Azure, Entra ID, Exchange, Fabric, and Partner Center. Six vulnerabilities scored a perfect 10/10, including elevation-of-privilege bugs in Azure SQL Database (CVE-2026-69502), Azure Arc, and Exchange Online, and remote code execution flaws in Azure Managed Instance for Apache Cassandra and Entra ID. Most fixes were applied server-side, requiring no customer action; Microsoft is also still working on a patch for the ShieldBreak Defender zero-day, tracked as CVE-2026-69414.

Quick Hits

Reply

Avatar

or to participate