TechLogHub Blog — Page 11 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
DAEMON Tools Devs Confirm Breach, Release Malware-Free Version
May 6, 2026

DAEMON Tools Devs Confirm Breach, Release Malware-Free Version

Disc Soft confirms a supply-chain attack that trojanized DAEMON Tools Lite installers, releasing a malware-free 12.6 version on May 5 while other DAEMON Tools products appear unaffected. Users who installed 12.5.1 since April 8 should uninstall, run a full scan, and upgrade to 12.6; prior activity linked by Kaspersky involved backdoors and info-stealers, but the latest 12.6.0.2445 is reported to no longer exhibit malicious behavior.

By TechLogHub
Why ransomware attacks succeed even when backups exist
May 6, 2026

Why ransomware attacks succeed even when backups exist

Ransomware now often defeats backups by exposing, compromising, or destroying backup systems during an attack, not because backups are absent. This post outlines the typical attack chain and why traditional backup strategies fail—shared credentials, weak access controls, lack of immutable backups, untested recovery, and siloed tools. It argues that immutability is critical but not sufficient on its own; it must be combined with strong access control, monitoring, and recovery validation. Five practical protections are recommended: enforce identity separation with MFA, isolate backup environments, use immutable backups, monitor backup activity, and regularly test restores. It also covers steps if backups are compromised, such as locating older clean copies, leveraging off-site immutable storage, and rebuilding from clean baselines. The piece advocates a resilience-first approach and an integrated cyber-protection platform that unifies backup, security, and recovery to achieve end-to-end visibility and reliable recovery in today’s threat landscape.

By TechLogHub
Palo Alto Networks Warns of Firewall RCE Zero-Day Exploited in Attacks
May 6, 2026

Palo Alto Networks Warns of Firewall RCE Zero-Day Exploited in Attacks

Palo Alto Networks warns of a critical unpatched zero-day in the PAN-OS User-ID Authentication Portal (Captive Portal), tracked as CVE-2026-0300. The flaw, a buffer overflow, could allow unauthenticated attackers to execute code with root privileges on internet-facing PA-Series and VM-Series firewalls via crafted packets. Limited exploitation has been observed, and admins are urged to restrict portal access or disable it until a patch is released. Shadowserver data show thousands of PAN-OS VM-series devices online, underscoring the widespread risk.

By TechLogHub
New stealthy Quasar Linux malware targets software developers
May 5, 2026

New stealthy Quasar Linux malware targets software developers

Trend Micro researchers have uncovered Quasar Linux (QLNX), a stealthy new Linux malware implant targeting software developers' environments (npm, PyPI, GitHub, AWS, Docker, Kubernetes) and signaling a potential supply-chain attack vector. QLNX combines rootkit, backdoor, and credential-stealing capabilities to achieve long-term, fileless persistence, including in-memory execution, log deletion, process-name spoofing, and forensic data clearing. It uses seven persistence mechanisms (LD_PRELOAD, systemd, crontab, init.d, XDG autostart, and .bashrc injection) to ensure it loads across dynamically linked processes. The malware comprises modular blocks: a 58-command RAT core, a dual-layer rootkit (userland LD_PRELOAD and kernel eBPF), credential harvesting (SSH keys, cloud/config files, PAM backdoors), surveillance (keylogging, screenshots), networking and lateral movement, in-memory execution/injection, and real-time filesystem monitoring. By targeting developer workstations, QLNX aims to bypass enterprise defenses and access credentials underpinning software delivery pipelines; while IoCs are provided, attribution and deployment scope remain unclear.

By TechLogHub
Instructure Breach: Hacker Claims Data Theft From 8,800 Schools and Universities
May 5, 2026

Instructure Breach: Hacker Claims Data Theft From 8,800 Schools and Universities

Extortion group ShinyHunters claims to have stolen 280 million records from 8,809 schools and education platforms via Instructure's Canvas, exposing students’ and staff’s names, emails, and private messages; while some institutions confirm investigations, Instructure has not publicly commented and the scope of impacted organizations remains unverified.

By TechLogHub
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
May 5, 2026

DAEMON Tools trojanized in supply-chain attack to deploy backdoor

Kaspersky reports a supply-chain attack that trojanized DAEMON Tools installers, delivering a backdoor to thousands of systems worldwide since April 8, 2026. The first-stage malware acts as an information stealer, while some victims received a second-stage payload—a lightweight backdoor capable of executing commands and downloading files, sometimes in memory. In at least one case, a more advanced QUIC RAT was deployed against a Russian educational institution. The campaign affected users in over 100 countries, but second-stage payloads targeted about a dozen high-value targets in sectors such as retail, science, government, and manufacturing in Russia, Belarus, and Thailand. Affected DAEMON Tools versions span 12.5.0.2421–12.5.0.2434, including DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe, and the attack is ongoing as of May 5, 2026. Organizations should audit systems with DAEMON Tools installed since April 8 and bolster supply-chain defenses.

By TechLogHub
Student hacked Taiwan high-speed rail to trigger emergency brakes
May 5, 2026

Student hacked Taiwan high-speed rail to trigger emergency brakes

Taiwanese university student arrested for hacking the Taiwan High-Speed Rail’s TETRA system by using software-defined radios and handheld radios to transmit a high-priority alarm, causing four THSR trains to halt for 48 minutes on April 5; an accomplice aided the plot; the 23-year-old faces up to 10 years’ imprisonment and was released on NT$100,000 bail.

By TechLogHub
Vimeo data breach exposes personal information of 119,000 people
May 5, 2026

Vimeo data breach exposes personal information of 119,000 people

Vimeo confirms a breach linked to Anodot that exposed personal data for about 119,000 people—email addresses and, in some cases, names—along with technical data, video titles, and metadata. The company says no video content, valid user credentials, or payment card information were compromised, and there were no service disruptions; Anodot credentials were disabled and the integration removed, with law enforcement notified. After Vimeo's disclosure, the ShinyHunters extortion group leaked a 106GB cache of stolen data on the dark web, claiming access via Anodot tokens and signaling a broader campaign against SaaS platforms.

By TechLogHub
Google now offers up to $1.5 million for some Android exploits
May 5, 2026

Google now offers up to $1.5 million for some Android exploits

Google is overhauling its Android and Chrome vulnerability rewards, offering up to $1.5 million for the hardest Android exploits (zero-click Pixel Titan M2 full-chain with persistence) and up to $750,000 without persistence, while Chrome rewards reach $250,000 plus a $250,128 bonus for MiraclePtr-protected memory. The program shifts toward concise, AI-friendly reports and focuses Android research on Linux-kernel vulnerabilities in Google-maintained components. Google notes a record $17.1 million paid in 2025 to 747 researchers, bringing total payouts since 2010 to $81.6 million, with 2026 payouts expected to rise. The Autonomous Validation Summit is scheduled for May 12–14, 2026.

By TechLogHub
Amazon SES increasingly abused in phishing to evade detection
May 4, 2026

Amazon SES increasingly abused in phishing to evade detection

Kaspersky reports a surge in phishing using Amazon SES to bypass security filters, fueled by widespread exposure of AWS credentials in public repos, Docker images, and backups. Attackers automate secret discovery (e.g., with TruffleHog) to validate keys and blast realistic phishing campaigns—including DocuSign-like notices and fake invoices—without triggering SPF/DKIM/DMARC blocks. Blocking SES IPs is ineffective since SES is a trusted service. Recommended mitigations: enforce least-privilege IAM, enable MFA, rotate keys regularly, apply IP-based access controls, and use encryption.

By TechLogHub
Backdoored PyTorch Lightning package drops credential stealer
May 4, 2026

Backdoored PyTorch Lightning package drops credential stealer

Security researchers disclosed a supply-chain attack in PyTorch Lightning: a compromised PyPI release (version 2.6.3) secretly downloads Bun and executes an obfuscated 11.4 MB JavaScript payload on import, delivering ShaiWorm, a credential-stealer that targets environment files, API keys, browser data, and cloud credentials (AWS/Azure/GCP) and can run arbitrary commands. Microsoft Defender blocked the payload on affected machines; maintainers have rolled back to version 2.6.1 and are auditing recent releases, with immediate secret rotation advised as the investigation continues.

By TechLogHub
Trellix discloses data breach after source code repository hack
May 4, 2026

Trellix discloses data breach after source code repository hack

Trellix disclosed a data breach after unauthorized access to a portion of its source code repository and is investigating with external forensics, reporting no evidence yet that the source code or its distribution process was compromised and that law enforcement has been notified; further details will be shared after the investigation. The incident comes amid other recent breaches at Checkmarx, Cisco, and HackerOne.

By TechLogHub
They don’t hack, they borrow: How fraudsters target credit unions
May 4, 2026

They don’t hack, they borrow: How fraudsters target credit unions

Flare researchers reveal a structured loan-fraud technique that targets small to mid-sized credit unions by borrowing identities rather than hacking systems. Attackers assemble stolen personal data, KBA answers, and credit histories to pass identity verification and loan checks, then move funds out quickly through intermediaries. The fraud workflow unfolds in eight steps—from identity acquisition to cash-out—designed to exploit weaknesses in onboarding and lending processes rather than software vulnerabilities. The report highlights higher risk for smaller lenders and urges proactive monitoring of exposed data sources to thwart such schemes.

By TechLogHub
Instructure Confirms Data Breach as ShinyHunters Claims Attack
May 3, 2026

Instructure Confirms Data Breach as ShinyHunters Claims Attack

Instructure confirms a cybersecurity incident affecting Canvas, with the ShinyHunters group claiming responsibility. The attackers say personal data from users at affected institutions—names, emails, student IDs, and messages—has been exposed. Instructure reports no current evidence of passwords, birth dates, government IDs, or financial information being compromised and has deployed patches, enhanced monitoring, and API key rotation requiring re-authorization for new keys. ShinyHunters’ data-leak listing cites roughly 240 million records across about 15,000 institutions and up to 275 million individuals, but independent verification of these figures is still pending.

By TechLogHub
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
May 3, 2026

Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha

Microsoft Defender flagged legitimate DigiCert root certificates as malware after a threat signature update on April 30, causing false positives and removals from the Windows trust store; two root certificates were reportedly affected, and Microsoft rolled out fixes in Security Intelligence updates (from 1.449.430.0 to 1.449.431.0) with automatic or manual update options; the incident occurs in the context of a DigiCert breach and is discussed as a potential link, though the flagged root certs are different from the revoked code-signing certificates.

By TechLogHub
Telegram Mini Apps Abused for Crypto Scams and Android Malware Delivery
May 3, 2026

Telegram Mini Apps Abused for Crypto Scams and Android Malware Delivery

Cybersecurity researchers have uncovered FEMITBOT, a Telegram-based fraud operation that uses Mini Apps and bots to run fake crypto platforms, impersonate brands (Apple, NVIDIA, Disney, eBay, IBM, Moon Pay, YouKu, and more), and deliver Android malware. The campaigns share a common backend, allow rapid branding/language changes, and use tracking pixels to optimize performance. Victims encounter fake dashboards and urgency tactics, then are urged to deposit funds or complete referrals; some Mini Apps push Android APKs masquerading as legitimate apps via the in-app browser. Users are advised to avoid crypto-promoting Telegram bots and sideloading APKs.

By TechLogHub
Critical cPanel flaw mass-exploited in "Sorry" ransomware attacks
May 2, 2026

Critical cPanel flaw mass-exploited in "Sorry" ransomware attacks

A critical vulnerability in cPanel/WHM (CVE-2026-41940) is being mass-exploited in the Sorry ransomware campaign. An emergency update for WHM and cPanel has been released, but attackers have already compromised tens of thousands of servers—at least 44,000 IPs according to Shadowserver—and deployed a Go-based Linux encryptor that appends the .sorry extension to files. Victims receive a ransom note with a Tox ID, and decryption requires the RSA-2048 private key; without it, decryption is effectively impossible. All cPanel/WHM users are urged to apply the security update immediately as exploitation continues to spread.

By TechLogHub
ConsentFix v3 Attacks Target Azure with Automated OAuth Abuse
May 2, 2026

ConsentFix v3 Attacks Target Azure with Automated OAuth Abuse

Researchers warn of ConsentFix v3, a new automated OAuth abuse campaign targeting Microsoft Azure. The refinement verifies Azure tenants, gathers employee details for impersonation, and coordinates phishing and exfiltration across services (Outlook, Tutanota, Cloudflare, DocSend, Hunter.io, and Pipedream) to capture OAuth codes and tokens. A Cloudflare Pages phishing page prompts a real Microsoft OAuth flow, with a Pipedream webhook receiving the code, exchanging it for tokens, and feeding them to Specter Portal to access compromised resources. Mitigations include token binding, behavioral detection, and app-auth restrictions, but the campaign’s reach and impact remain unclear.

By TechLogHub
Microsoft tests modern Windows Run, says it's faster than legacy dialog
May 1, 2026

Microsoft tests modern Windows Run, says it's faster than legacy dialog

Microsoft previews a modern Run dialog for Windows 11 in build 26300.8346, featuring Fluent Design, built-in dark mode, and a faster median time-to-show of 94ms compared with 103ms for the legacy Run. The Browse button is removed after usage analysis; the new dialog supports quick access to the home directory (~) and shows icons for easier entry identification. Activation is optional via Settings > Advanced Settings, and Microsoft is collecting feedback before broader rollout. The preview also includes changes to Windows Share UI for AAD users and expanded Magnifier zoom presets, with broader release planned in the coming months through the Experimental Channel.

By TechLogHub
Edu tech firm Instructure discloses cyber incident, probes impact
May 1, 2026

Edu tech firm Instructure discloses cyber incident, probes impact

Instructure, the maker of Canvas, has disclosed a cybersecurity incident and says it is actively investigating with outside forensics experts. Some services, including Canvas Data 2 and Canvas Beta, have been under maintenance since May 1 as the company assesses impact, though it has not said whether the maintenance is related to the breach. The incident underscores a trend of education-technology breaches, following PowerSchool’s 2025 breach and a September 2025 Instructure Salesforce attack attributed to ShinyHunters.

By TechLogHub

Showing 20 of 423 articles