TechLogHub Blog — Page 13 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
Inside an OPSEC Playbook: How Threat Actors Evade Detection
Apr 28, 2026

Inside an OPSEC Playbook: How Threat Actors Evade Detection

Flare researchers examine a cybercrime forum post in which a threat actor outlines a three-tier OPSEC framework for high-volume carding aimed at staying undetected over time. The Public Layer uses clean devices and rotated residential IPs; the Operational Layer is strictly isolated with encrypted containers and hardware-backed keys; the Extraction Layer keeps cashout systems isolated to break the forensic chain. The post highlights recurring mistakes—identity reuse, weak fingerprinting evasion, poor separation of stages, and metadata exposure—and introduces advanced resilience techniques such as time-delayed triggers, behavioral randomization, distributed verification, and dead man’s switches. Defenders are offered actionable takeaways: improve cross-platform identity correlation, evolve behavioral analytics, monitor the full attack chain, leverage metadata, and prepare for resilient adversaries. The material argues that OPSEC is becoming a competitive advantage in cybercrime, prioritizing longevity and stealth over short-term access.

By TechLogHub
Microsoft: New Remote Desktop warnings may display incorrectly
Apr 28, 2026

Microsoft: New Remote Desktop warnings may display incorrectly

Microsoft confirms a new issue where security warnings for Remote Desktop (.rdp) files display incorrectly after the April 2026 updates, affecting Windows 11, Windows 10, and Windows Server. The problem is especially prevalent on systems with multiple monitors using different display scaling, causing unreadable text and misaligned buttons in the warning dialogs. The April 2026 safeguards introduce a one-time educational prompt, followed by a pre-connection security dialog that shows publisher status, remote address, and local resource redirections (all disabled by default). Unsigned RDP files trigger a "Caution: Unknown remote connection" warning. The article notes that threat actors have abused RDP files in phishing campaigns, including past use by the APT29 group.

By TechLogHub
Microsoft asks iPhone users to reauthenticate after Outlook outage
Apr 28, 2026

Microsoft asks iPhone users to reauthenticate after Outlook outage

Microsoft has resolved a global Outlook.com outage that affected users worldwide and now requires iPhone users to re-authenticate their accounts in the iOS Mail app to regain access. The company cited a recently introduced change as the cause but did not disclose specifics or the scope, with service returning to normal around 7 PM UTC on April 27, 2026. The report notes related past outages—such as March’s Exchange Online issues and Copilot sign-in problems—and ongoing Microsoft 365 reliability efforts.

By TechLogHub
Robinhood Account Creation Flaw Abused to Send Phishing Emails
Apr 27, 2026

Robinhood Account Creation Flaw Abused to Send Phishing Emails

Robinhood’s account-creation process was abused to inject HTML into onboarding emails, allowing phishers to embed a convincing “Unrecognized Device” message and direct users to a phishing site. Attackers used known customer email lists from prior breaches and Gmail dot aliasing to send emails from a legitimate [email protected] address with SPF/DKIM, prompting users to review activity. Robinhood says the incident did not involve a system or account breach and has removed the Device: field from onboarding emails; recipients are advised to delete the message and avoid clicking links.

By TechLogHub
GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions
Apr 27, 2026

GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions

GlassWorm malware returns to OpenVSX with 73 “sleeper” extensions that look benign until they update, delivering a malicious payload. Six extensions are active so far; the rest appear dormant or suspicious. The extensions clone legitimate listings and function as loaders, fetching the payload from GitHub, loading platform-specific modules, or using obfuscated JavaScript at runtime. This wave signals a shift from embedding malware to delivering it on update. Researchers note the campaign previously targeted wallets and credentials and mid-March 2026 saw hundreds of repos affected; a full list of the 73 extensions has been published, and developers are urged to rotate secrets and clean their environments.

By TechLogHub
Canada arrests three for operating “SMS blaster” device in Toronto
Apr 27, 2026

Canada arrests three for operating “SMS blaster” device in Toronto

Canadian authorities have arrested three men in Toronto for operating an "SMS blaster" that mimics a cellular tower to send phishing texts. The rogue base stations, which can move across the Greater Toronto Area, allegedly entrapged about 13 million mobile users and could disconnect devices from legitimate networks, potentially hindering emergency services. The investigation, dubbed Project Lighthouse, began in November 2025; two suspects were arrested March 31 in Markham and Hamilton, with a third turning himself in on April 21. This is the first known sighting of such a device in Canada. Officials advise treating SMS as insecure, avoiding links in texts, and using end-to-end encrypted channels for sensitive communications, while noting that disabling 2G downgrades is recommended as an additional precaution.

By TechLogHub
Alleged Silk Typhoon Hacker Extradited to the U.S. for Cyberespionage
Apr 27, 2026

Alleged Silk Typhoon Hacker Extradited to the U.S. for Cyberespionage

Xu Zewei, a Chinese national alleged to have carried out cyberespionage for China's Ministry of State Security and linked to the Silk Typhoon/Hafnium group, has been extradited from Italy to the United States to face criminal charges. U.S. prosecutors say he conducted intrusions from February 2020 to June 2021, including targeting COVID-19 research and exploiting Microsoft Exchange Server zero-days, while working as a contracted hacker for Shanghai Powerock Network under MSS direction; he was previously arrested in Milan in 2025 at the U.S. request for ties to Silk Typhoon.

By TechLogHub
PyPI package with 1.1M monthly downloads hacked to push infostealer
Apr 27, 2026

PyPI package with 1.1M monthly downloads hacked to push infostealer

Attackers pushed a poisoned PyPI release of the elementary-data package (0.23.3) and a related Docker image to steal sensitive data and cryptocurrency wallets. The compromise exploited a GitHub Actions script-injection flaw in a pull request, exposing the workflow’s GITHUB_TOKEN and allowing a forged commit and tag to trigger the legitimate release pipeline. A clean replacement, elementary-data 0.23.4, was released, but users who installed 0.23.3 remain compromised, as the payload (elementary.pth) could exfiltrate SSH keys, credentials, cloud and Kubernetes secrets, environment tokens, and wallet files. With 1.1 million+ monthly downloads, affected users should rotate all secrets and restore from a safe point.

By TechLogHub
Microsoft rolls out revamped Windows Insider Program
Apr 25, 2026

Microsoft rolls out revamped Windows Insider Program

Microsoft is revamping the Windows Insider Program to two channels—Experimental (replacing Dev/Canary) and Beta—to simplify testing and address Windows 11 reliability concerns. Beta will deliver features immediately while Experimental uses feature flags you can toggle in Settings; the rollout will happen in phases with specific builds for each channel.

By TechLogHub
UNC6692 Uses Microsoft Teams to Deploy Snow Malware
Apr 25, 2026

UNC6692 Uses Microsoft Teams to Deploy Snow Malware

UNC6692 has deployed a new malware suite called Snow via Microsoft Teams, using social engineering and email bombing to entice victims. The Snow family consists of SnowBelt (a Chrome extension for persistence), SnowBasin (a backdoor), and SnowGlaze (a tunneler/C2 conduit). After compromising a network, the group performs internal reconnaissance, dumps LSASS memory, uses pass-the-hash, and exfiltrates Active Directory data (via LimeWire), enabling lateral movement and domain takeover. Mandiant provides IoCs and YARA rules to help detect Snow.

By TechLogHub
ADT confirms data breach after ShinyHunters leak threat
Apr 24, 2026

ADT confirms data breach after ShinyHunters leak threat

ADT confirms a data breach after a ShinyHunters extortion threat, detecting unauthorized access on April 20, 2026 and concluding personal data was stolen. The exposed information includes names, phone numbers, and addresses, with a small percentage containing dates of birth and the last four digits of Social Security numbers or Tax IDs; payment data was not accessed and customer security systems were not affected. ShinyHunters claimed as many as 10 million records were stolen and threatened to leak the data unless a ransom is paid. The attackers allegedly used a vishing campaign to compromise an employee’s Okta SSO and accessed Salesforce data. ADT says it has contacted all affected individuals.

By TechLogHub
New ‘Pack2TheRoot’ flaw gives hackers root Linux access
Apr 24, 2026

New ‘Pack2TheRoot’ flaw gives hackers root Linux access

Researchers have disclosed Pack2TheRoot, a local privilege escalation vulnerability (CVE-2026-41651) in the PackageKit daemon that could let an unprivileged Linux user install or remove system packages and gain root. The flaw has persisted since 2014 in PackageKit 1.0.2 through 1.3.4 and is being mitigated by PackageKit 1.3.5. Affected distributions include Ubuntu (18.04–26.x), Debian, Rocky Linux, and Fedora; other PackageKit–using systems may be vulnerable. Users should upgrade to PackageKit 1.3.5, verify packagekit version with dpkg -l | grep packagekit (or rpm -qa), and check the PackageKit daemon status with systemctl status packagekit or pkmon. The Deutsche Telekom Red Team uncovered that certain commands could bypass authentication on Fedora, enabling privilege escalation; details and PoC are redacted to allow patch propagation.

By TechLogHub
DORA and operational resilience: Credential management as a financial risk control
Apr 24, 2026

DORA and operational resilience: Credential management as a financial risk control

EU’s Digital Operational Resilience Act (DORA) Article 9 makes credential security a binding financial risk control for banks and financial institutions, emphasizing that stolen credentials are the top initial access vector and can enable months of unseen operational disruption. The post breaks down Article 9 requirements—phishing-resistant MFA (FIDO2/WebAuthn), least-privilege access with just-in-time provisioning, and cryptographic key protection with encrypted credential vaults—and maps them to practical controls like PAM, session recording, and comprehensive audit trails. It uses breaches (France’s national bank registry and Santander’s vendor-based Snowflake breach) to illustrate regulatory exposure and the risk of vendor credentials. A four-part program is proposed: deploy phishing-resistant MFA, enforce least privilege, vault all credentials, and monitor continuously. Passwork is highlighted as a self-hosted, ISO 27001-certified solution that supports these controls and provides audit-ready logs, with an emphasis on audit preparation to satisfy regulators.

By TechLogHub
Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks
Apr 24, 2026

Over 10,000 Zimbra servers vulnerable to ongoing XSS attacks

More than 10,000 Zimbra Collaboration Suite installations exposed online remain vulnerable to an ongoing XSS flaw (CVE-2025-48700), risking unauthenticated data exposure via JavaScript in user sessions. Affected versions include ZCS 8.8.15, 9.0, 10.0, and 10.1; patches were released by Synacor in June 2025. CISA has flagged the vulnerability as exploited in the wild and added it to the Known Exploited Vulnerabilities catalog, with federal agencies ordered to patch by April 23, 2026. Shadowserver reports about 10,500 unpatched servers, concentrated in Asia and Europe. The situation echoes past Zimbra abuses by state-backed groups (e.g., APT28, Cozy Bear) in phishing and credential-stealing campaigns, underscoring ongoing risk to governments and enterprises.

By TechLogHub
Microsoft now lets admins uninstall Copilot on enterprise devices
Apr 24, 2026

Microsoft now lets admins uninstall Copilot on enterprise devices

Microsoft has introduced a new policy, Remove Microsoft Copilot App, that lets IT admins uninstall the Copilot assistant from managed Windows devices. The policy, available as a Policy CSP and via Group Policy after the April 2026 Patch Tuesday, targets Windows 11 25H2 devices where the Microsoft 365 Copilot and Copilot are installed, the user did not install the Copilot app themselves, and Copilot hasn’t been launched in the prior 28 days; it is deployable through Intune or SCCM and uninstalls Copilot non-disruptively, though users can reinstall if they choose.

By TechLogHub
Trigona Ransomware Attacks Use Custom Exfiltration Tool to Steal Data
Apr 23, 2026

Trigona Ransomware Attacks Use Custom Exfiltration Tool to Steal Data

Trigona ransomware operators are now using a custom command-line exfiltration tool, uploader_client.exe, to steal data more quickly from compromised networks. The tool connects to a hardcoded server, supports up to five parallel uploads per file, rotates TCP connections after 2GB of traffic, and can selectively exfiltrate certain file types while requiring an authentication key to access stolen data. The March attacks attributed to a gang affiliate signal a shift from publicly available tools to proprietary malware to stay under security monitoring. In these campaigns, Trigona also deploys the Huorong Network Security Suite’s HRSword kernel driver, tools to disable security products, PowerRun for elevated execution, AnyDesk for remote access, and credential tools like Mimikatz and Nirsoft. Symantec provides IoCs to aid detection and blocking of these activities.

By TechLogHub
New Checkmarx supply-chain breach affects KICS analysis tool
Apr 23, 2026

New Checkmarx supply-chain breach affects KICS analysis tool

Security researchers have disclosed a supply-chain breach affecting Checkmarx KICS, compromising official Docker images and VS Code/Open VSX extensions to harvest secrets from developer environments. The attack uses a hidden MCP addon to steal GitHub tokens, cloud credentials, npm tokens, SSH keys, and environment variables, encrypting and exfiltrating them to a spoofed audit.checkmarx.cx domain, with automatically created GitHub repos for data leakage. The malicious activity was active on 2026-04-22 from 14:17:59 to 15:41:31 UTC; affected tags have been restored and the fake v2.1.21 tag removed. Checkmarx has rotated exposed credentials and removed artifacts; users should rotate secrets, rebuild from known safe baselines, block exfiltration endpoints, and use pinned SHAs. Safe versions include DockerHub KICS v2.1.20 and updated extensions.

By TechLogHub
Kyber ransomware gang toys with post-quantum encryption on Windows
Apr 22, 2026

Kyber ransomware gang toys with post-quantum encryption on Windows

Rapid7 reveals a new Kyber ransomware operation targeting Windows and VMware ESXi, with one variant claiming post-quantum Kyber1024 encryption. Two variants were observed in March 2026 using the same campaign ID and Tor-based infrastructure: a Windows Rust-based encryptor that uses Kyber1024 (and X25519) to protect AES-CTR bulk encryption, and an ESXi-focused variant that encrypts datastore files, can terminate VMs, and deface management interfaces. The Windows payload appends the .#~~~ extension, shuts down services, deletes backups, wipes event logs, and can terminate Hyper-V VMs; the ESXi variant enumerates VMs, encrypts datastores, and defaces interfaces. A Linux ESXi variant reportedly uses ChaCha8 with RSA-4096 for key wrapping. Despite Kyber1024 branding, Rapid7 notes Kyber is not used for direct file encryption; files are effectively unrecoverable without the attacker key. So far, at least one victim is publicly listed—a large U.S. defense contractor and IT services provider.

By TechLogHub
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process
Apr 22, 2026

Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process

This post exposes Caller-as-a-Service, a structured, scalable fraud operation that treats phone scams like a professional business. It maps a full attack lifecycle with distinct roles—from data sourcing and infrastructure to live-call agents—supervision, and varied compensation models. It explains underground recruitment tactics (including “proof-of-profit” visuals and English-language targeting), how stolen data fuels campaigns, and the shift toward industrialized social engineering. The piece also outlines defender and individual implications, recommending stronger identity verification, behavioral analytics, and MFA, and it highlights Flare’s ability to detect leaked data and recruitment activity to preempt attacks.

By TechLogHub
Microsoft Releases Emergency Patches for Critical ASP.NET Core Privilege Escalation Flaw
Apr 22, 2026

Microsoft Releases Emergency Patches for Critical ASP.NET Core Privilege Escalation Flaw

Microsoft issued out-of-band security updates to patch a critical ASP.NET Core Data Protection vulnerability (CVE-2026-40372) that could allow attackers to forge authentication cookies and escalate to SYSTEM privileges. The flaw stems from a regression in DataProtection packages 10.0.0–10.0.6, where the HMAC validation used the wrong bytes, enabling forged payloads to bypass authenticity checks and decrypt prior payloads in auth cookies, antiforgery tokens, TempData, and OIDC state. If exploited, attackers could impersonate a privileged user and cause the app to issue legitimately signed tokens to themselves; those tokens remain valid after upgrading unless the DataProtection key ring is rotated. Microsoft urges updating Microsoft.AspNetCore.DataProtection to 10.0.7 and redeploying to reject forged payloads, and to rotate the key ring to invalidate any minted tokens. The advisory notes the vulnerability can also enable file disclosure and data modification, without impacting system availability. Related context includes earlier CVE-2025-55315 and other Windows Server updates released in April 2026.

By TechLogHub

Showing 20 of 423 articles