TechLogHub Blog — Page 11 of 22
Insights, guides, and product strategy for builders and product teams.

DAEMON Tools Devs Confirm Breach, Release Malware-Free Version
Disc Soft confirms a supply-chain attack that trojanized DAEMON Tools Lite installers, releasing a malware-free 12.6 version on May 5 while other DAEMON Tools products appear unaffected. Users who installed 12.5.1 since April 8 should uninstall, run a full scan, and upgrade to 12.6; prior activity linked by Kaspersky involved backdoors and info-stealers, but the latest 12.6.0.2445 is reported to no longer exhibit malicious behavior.

Why ransomware attacks succeed even when backups exist
Ransomware now often defeats backups by exposing, compromising, or destroying backup systems during an attack, not because backups are absent. This post outlines the typical attack chain and why traditional backup strategies fail—shared credentials, weak access controls, lack of immutable backups, untested recovery, and siloed tools. It argues that immutability is critical but not sufficient on its own; it must be combined with strong access control, monitoring, and recovery validation. Five practical protections are recommended: enforce identity separation with MFA, isolate backup environments, use immutable backups, monitor backup activity, and regularly test restores. It also covers steps if backups are compromised, such as locating older clean copies, leveraging off-site immutable storage, and rebuilding from clean baselines. The piece advocates a resilience-first approach and an integrated cyber-protection platform that unifies backup, security, and recovery to achieve end-to-end visibility and reliable recovery in today’s threat landscape.

Palo Alto Networks Warns of Firewall RCE Zero-Day Exploited in Attacks
Palo Alto Networks warns of a critical unpatched zero-day in the PAN-OS User-ID Authentication Portal (Captive Portal), tracked as CVE-2026-0300. The flaw, a buffer overflow, could allow unauthenticated attackers to execute code with root privileges on internet-facing PA-Series and VM-Series firewalls via crafted packets. Limited exploitation has been observed, and admins are urged to restrict portal access or disable it until a patch is released. Shadowserver data show thousands of PAN-OS VM-series devices online, underscoring the widespread risk.

New stealthy Quasar Linux malware targets software developers
Trend Micro researchers have uncovered Quasar Linux (QLNX), a stealthy new Linux malware implant targeting software developers' environments (npm, PyPI, GitHub, AWS, Docker, Kubernetes) and signaling a potential supply-chain attack vector. QLNX combines rootkit, backdoor, and credential-stealing capabilities to achieve long-term, fileless persistence, including in-memory execution, log deletion, process-name spoofing, and forensic data clearing. It uses seven persistence mechanisms (LD_PRELOAD, systemd, crontab, init.d, XDG autostart, and .bashrc injection) to ensure it loads across dynamically linked processes. The malware comprises modular blocks: a 58-command RAT core, a dual-layer rootkit (userland LD_PRELOAD and kernel eBPF), credential harvesting (SSH keys, cloud/config files, PAM backdoors), surveillance (keylogging, screenshots), networking and lateral movement, in-memory execution/injection, and real-time filesystem monitoring. By targeting developer workstations, QLNX aims to bypass enterprise defenses and access credentials underpinning software delivery pipelines; while IoCs are provided, attribution and deployment scope remain unclear.

Instructure Breach: Hacker Claims Data Theft From 8,800 Schools and Universities
Extortion group ShinyHunters claims to have stolen 280 million records from 8,809 schools and education platforms via Instructure's Canvas, exposing students’ and staff’s names, emails, and private messages; while some institutions confirm investigations, Instructure has not publicly commented and the scope of impacted organizations remains unverified.

DAEMON Tools trojanized in supply-chain attack to deploy backdoor
Kaspersky reports a supply-chain attack that trojanized DAEMON Tools installers, delivering a backdoor to thousands of systems worldwide since April 8, 2026. The first-stage malware acts as an information stealer, while some victims received a second-stage payload—a lightweight backdoor capable of executing commands and downloading files, sometimes in memory. In at least one case, a more advanced QUIC RAT was deployed against a Russian educational institution. The campaign affected users in over 100 countries, but second-stage payloads targeted about a dozen high-value targets in sectors such as retail, science, government, and manufacturing in Russia, Belarus, and Thailand. Affected DAEMON Tools versions span 12.5.0.2421–12.5.0.2434, including DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe, and the attack is ongoing as of May 5, 2026. Organizations should audit systems with DAEMON Tools installed since April 8 and bolster supply-chain defenses.

Student hacked Taiwan high-speed rail to trigger emergency brakes
Taiwanese university student arrested for hacking the Taiwan High-Speed Rail’s TETRA system by using software-defined radios and handheld radios to transmit a high-priority alarm, causing four THSR trains to halt for 48 minutes on April 5; an accomplice aided the plot; the 23-year-old faces up to 10 years’ imprisonment and was released on NT$100,000 bail.

Vimeo data breach exposes personal information of 119,000 people
Vimeo confirms a breach linked to Anodot that exposed personal data for about 119,000 people—email addresses and, in some cases, names—along with technical data, video titles, and metadata. The company says no video content, valid user credentials, or payment card information were compromised, and there were no service disruptions; Anodot credentials were disabled and the integration removed, with law enforcement notified. After Vimeo's disclosure, the ShinyHunters extortion group leaked a 106GB cache of stolen data on the dark web, claiming access via Anodot tokens and signaling a broader campaign against SaaS platforms.

Google now offers up to $1.5 million for some Android exploits
Google is overhauling its Android and Chrome vulnerability rewards, offering up to $1.5 million for the hardest Android exploits (zero-click Pixel Titan M2 full-chain with persistence) and up to $750,000 without persistence, while Chrome rewards reach $250,000 plus a $250,128 bonus for MiraclePtr-protected memory. The program shifts toward concise, AI-friendly reports and focuses Android research on Linux-kernel vulnerabilities in Google-maintained components. Google notes a record $17.1 million paid in 2025 to 747 researchers, bringing total payouts since 2010 to $81.6 million, with 2026 payouts expected to rise. The Autonomous Validation Summit is scheduled for May 12–14, 2026.

Amazon SES increasingly abused in phishing to evade detection
Kaspersky reports a surge in phishing using Amazon SES to bypass security filters, fueled by widespread exposure of AWS credentials in public repos, Docker images, and backups. Attackers automate secret discovery (e.g., with TruffleHog) to validate keys and blast realistic phishing campaigns—including DocuSign-like notices and fake invoices—without triggering SPF/DKIM/DMARC blocks. Blocking SES IPs is ineffective since SES is a trusted service. Recommended mitigations: enforce least-privilege IAM, enable MFA, rotate keys regularly, apply IP-based access controls, and use encryption.

Backdoored PyTorch Lightning package drops credential stealer
Security researchers disclosed a supply-chain attack in PyTorch Lightning: a compromised PyPI release (version 2.6.3) secretly downloads Bun and executes an obfuscated 11.4 MB JavaScript payload on import, delivering ShaiWorm, a credential-stealer that targets environment files, API keys, browser data, and cloud credentials (AWS/Azure/GCP) and can run arbitrary commands. Microsoft Defender blocked the payload on affected machines; maintainers have rolled back to version 2.6.1 and are auditing recent releases, with immediate secret rotation advised as the investigation continues.

Trellix discloses data breach after source code repository hack
Trellix disclosed a data breach after unauthorized access to a portion of its source code repository and is investigating with external forensics, reporting no evidence yet that the source code or its distribution process was compromised and that law enforcement has been notified; further details will be shared after the investigation. The incident comes amid other recent breaches at Checkmarx, Cisco, and HackerOne.

They don’t hack, they borrow: How fraudsters target credit unions
Flare researchers reveal a structured loan-fraud technique that targets small to mid-sized credit unions by borrowing identities rather than hacking systems. Attackers assemble stolen personal data, KBA answers, and credit histories to pass identity verification and loan checks, then move funds out quickly through intermediaries. The fraud workflow unfolds in eight steps—from identity acquisition to cash-out—designed to exploit weaknesses in onboarding and lending processes rather than software vulnerabilities. The report highlights higher risk for smaller lenders and urges proactive monitoring of exposed data sources to thwart such schemes.

Instructure Confirms Data Breach as ShinyHunters Claims Attack
Instructure confirms a cybersecurity incident affecting Canvas, with the ShinyHunters group claiming responsibility. The attackers say personal data from users at affected institutions—names, emails, student IDs, and messages—has been exposed. Instructure reports no current evidence of passwords, birth dates, government IDs, or financial information being compromised and has deployed patches, enhanced monitoring, and API key rotation requiring re-authorization for new keys. ShinyHunters’ data-leak listing cites roughly 240 million records across about 15,000 institutions and up to 275 million individuals, but independent verification of these figures is still pending.

Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
Microsoft Defender flagged legitimate DigiCert root certificates as malware after a threat signature update on April 30, causing false positives and removals from the Windows trust store; two root certificates were reportedly affected, and Microsoft rolled out fixes in Security Intelligence updates (from 1.449.430.0 to 1.449.431.0) with automatic or manual update options; the incident occurs in the context of a DigiCert breach and is discussed as a potential link, though the flagged root certs are different from the revoked code-signing certificates.

Telegram Mini Apps Abused for Crypto Scams and Android Malware Delivery
Cybersecurity researchers have uncovered FEMITBOT, a Telegram-based fraud operation that uses Mini Apps and bots to run fake crypto platforms, impersonate brands (Apple, NVIDIA, Disney, eBay, IBM, Moon Pay, YouKu, and more), and deliver Android malware. The campaigns share a common backend, allow rapid branding/language changes, and use tracking pixels to optimize performance. Victims encounter fake dashboards and urgency tactics, then are urged to deposit funds or complete referrals; some Mini Apps push Android APKs masquerading as legitimate apps via the in-app browser. Users are advised to avoid crypto-promoting Telegram bots and sideloading APKs.

Critical cPanel flaw mass-exploited in "Sorry" ransomware attacks
A critical vulnerability in cPanel/WHM (CVE-2026-41940) is being mass-exploited in the Sorry ransomware campaign. An emergency update for WHM and cPanel has been released, but attackers have already compromised tens of thousands of servers—at least 44,000 IPs according to Shadowserver—and deployed a Go-based Linux encryptor that appends the .sorry extension to files. Victims receive a ransom note with a Tox ID, and decryption requires the RSA-2048 private key; without it, decryption is effectively impossible. All cPanel/WHM users are urged to apply the security update immediately as exploitation continues to spread.

ConsentFix v3 Attacks Target Azure with Automated OAuth Abuse
Researchers warn of ConsentFix v3, a new automated OAuth abuse campaign targeting Microsoft Azure. The refinement verifies Azure tenants, gathers employee details for impersonation, and coordinates phishing and exfiltration across services (Outlook, Tutanota, Cloudflare, DocSend, Hunter.io, and Pipedream) to capture OAuth codes and tokens. A Cloudflare Pages phishing page prompts a real Microsoft OAuth flow, with a Pipedream webhook receiving the code, exchanging it for tokens, and feeding them to Specter Portal to access compromised resources. Mitigations include token binding, behavioral detection, and app-auth restrictions, but the campaign’s reach and impact remain unclear.

Microsoft tests modern Windows Run, says it's faster than legacy dialog
Microsoft previews a modern Run dialog for Windows 11 in build 26300.8346, featuring Fluent Design, built-in dark mode, and a faster median time-to-show of 94ms compared with 103ms for the legacy Run. The Browse button is removed after usage analysis; the new dialog supports quick access to the home directory (~) and shows icons for easier entry identification. Activation is optional via Settings > Advanced Settings, and Microsoft is collecting feedback before broader rollout. The preview also includes changes to Windows Share UI for AAD users and expanded Magnifier zoom presets, with broader release planned in the coming months through the Experimental Channel.

Edu tech firm Instructure discloses cyber incident, probes impact
Instructure, the maker of Canvas, has disclosed a cybersecurity incident and says it is actively investigating with outside forensics experts. Some services, including Canvas Data 2 and Canvas Beta, have been under maintenance since May 1 as the company assesses impact, though it has not said whether the maintenance is related to the breach. The incident underscores a trend of education-technology breaches, following PowerSchool’s 2025 breach and a September 2025 Instructure Salesforce attack attributed to ShinyHunters.
Showing 20 of 423 articles


