TechLogHub Blog — Page 15 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
US nationals behind DPRK IT worker 'laptop farm' sent to prison
Apr 16, 2026

US nationals behind DPRK IT worker 'laptop farm' sent to prison

Two U.S. nationals, Kejia Wang and Zhenxing Wang, were sentenced for aiding North Korean IT workers to pose as American residents and gain employment at more than 100 U.S. firms, including Fortune 500 companies. The pair helped generate over $5 million in illicit revenue for the DPRK and caused about $3 million in damages by using stolen identities of more than 80 U.S. citizens, aided by fake companies and shell entities. Zhenxing Wang also hosted company laptops in U.S. homes to give DPRK workers access to corporate networks. Nine other defendants remain at large with rewards up to $5 million; the case underscores ongoing U.S. efforts to disrupt North Korea’s money-laundering and cyber operations that fund its weapons program.

By TechLogHub
Cisco says critical Webex Services flaw requires customer action
Apr 16, 2026

Cisco says critical Webex Services flaw requires customer action

Cisco issues security updates patching four critical flaws in Webex Services, including CVE-2026-20184 in the SSO integration with Control Hub that could allow remote impersonation; affected customers must upload a new SAML certificate to their IdP in Control Hub to prevent service disruption. The release also fixes three critical ISE vulnerabilities (CVE-2026-20147, 20180, 20186) that could enable arbitrary code execution, though exploitation requires admin credentials. Cisco’s PSIRT found no evidence of active exploitation; the advisory follows a prior CISA directive to patch a max-severity FMC flaw (CVE-2026-20131) used in zero-day Interlock attacks. The update bundle also covers ten additional medium-severity flaws that could bypass authentication, escalate privileges, or cause DoS.

By TechLogHub
Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face
Apr 16, 2026

Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face

Hackers are exploiting the Marimo pre-auth RCE (CVE-2026-39987) to deploy a new NKAbuse variant via Hugging Face Spaces, using a dropper script and a kagent binary to gain persistence and remote command access; upgrade Marimo to 0.23.0+ or block the /terminal/ws endpoint to mitigate.

By TechLogHub
New Microsoft Defender "RedSun" zero-day PoC grants SYSTEM privileges
Apr 16, 2026

New Microsoft Defender "RedSun" zero-day PoC grants SYSTEM privileges

Security researcher Chaotic Eclipse has released a proof-of-concept for RedSun, a new Microsoft Defender zero-day that can grant SYSTEM privileges on Windows 10, Windows 11, and Windows Server 2019 and later—even on fully patched systems with Defender enabled. The PoC abuses Defender's Cloud Files API to overwrite a protected system file by embedding an EICAR string, using an oplock to beat a volume shadow copy race, and employing a directory junction/reparse point to redirect the rewrite to C:WindowsSystem32TieringEngineService.exe, causing the attacker-controlled TieringEngineService.exe to run as SYSTEM. Analyst Will Dormann has confirmed the exploit works on patched machines. This follows the earlier BlueHammer LPE (CVE-2026-33825) fixed in April. The researcher says the publications are a protest at Microsoft’s vulnerability-disclosure process to MSRC; Microsoft emphasizes its commitment to coordinated disclosure and customer protection.

By TechLogHub
Signed software abused to deploy antivirus-killing scripts
Apr 15, 2026

Signed software abused to deploy antivirus-killing scripts

Security researchers have exposed a digitally signed adware campaign that silently disables antivirus protections by deploying SYSTEM-privileged payloads via an MSI/PowerShell updater built with Advanced Installer. In a single day, about 23,500 hosts in 124 countries were infected, including networks in academia, government, utilities, and healthcare, with the operator Dragon Boss Solutions LLC. The campaign uses PUPs branded as browsers, downloads an MSI disguised as a GIF, and runs ClockRemoval.ps1 to disable security products and block updates, raising the risk of more dangerous payloads; admins are urged to hunt for specific artifacts (MbRemoval/MbSetup, WMI subscriptions, and suspicious hosts-file changes) and to monitor unregistered update domains.

By TechLogHub
Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest
Apr 15, 2026

Microsoft pays $2.3M for cloud and AI flaws at Zero Day Quest

Microsoft awarded $2.3 million to security researchers after nearly 700 submissions to this year’s Zero Day Quest, with more than 80 high‑impact cloud and AI flaws uncovered during a live Redmond event. Researchers from 20+ countries tested in authorized environments, identifying paths such as credential exposure, SSRF chains, and cross‑tenant access; the contest is part of the Secure Future Initiative and continues to expand its $5 million prize pool aimed at strengthening cloud and AI security.

By TechLogHub
Microsoft: April updates trigger BitLocker key prompts on some servers
Apr 15, 2026

Microsoft: April updates trigger BitLocker key prompts on some servers

Microsoft has confirmed that the April 2026 security update (KB5082063) can trigger BitLocker recovery prompts on some Windows Server 2025 devices after restart. The issue affects a narrow set of enterprise configurations involving BitLocker on the OS drive, a PCR7-based TPM validation policy, and certain Secure Boot states, and is unlikely to impact typical consumer devices. Workarounds include removing the PCR7 Group Policy before updating or applying a Known Issue Rollback; Microsoft is developing a fix.

By TechLogHub
Microsoft fixes bug behind Windows Server 2025 automatic upgrades
Apr 15, 2026

Microsoft fixes bug behind Windows Server 2025 automatic upgrades

Microsoft has fixed the bug that caused Windows Server 2019 and 2022 systems to unexpectedly upgrade to Windows Server 2025. The issue, tied to third‑party update tools and a Windows Update banner, was first acknowledged in September 2024; Microsoft says the upgrade offer is now re-enabled in Windows Update Settings for in‑place upgrades. The article also notes recent out‑of‑band updates addressing other Windows issues.

By TechLogHub
Microsoft Adds Windows Protections for Malicious Remote Desktop Files
Apr 14, 2026

Microsoft Adds Windows Protections for Malicious Remote Desktop Files

Microsoft has added protections in the April 2026 Windows updates to defend against phishing campaigns that abuse Remote Desktop (.rdp) files. The changes introduce a one-time educational prompt on first open and future security dialogs showing publisher verification and a list of local resource redirections, with risky actions disabled by default. These protections apply to RDP files opened directly (not via the Remote Desktop client); admins can disable them via a registry key, but keeping them enabled is strongly recommended due to widespread abuse of RDP file functionality.

By TechLogHub
Kraken Extorted by Hackers After Insider Breach
Apr 14, 2026

Kraken Extorted by Hackers After Insider Breach

Kraken says it is being extorted by criminals who threaten to release videos showing internal systems with client data after an insider access incident by a support employee. The breach did not involve client funds and affected about 2,000 accounts (roughly 0.02% of Kraken’s users). Kraken will not pay or negotiate and is cooperating with federal law enforcement to prosecute those involved, underscoring insider-threat risks in crypto.

By TechLogHub
Over 100 Chrome extensions in Web Store target users accounts and data
Apr 14, 2026

Over 100 Chrome extensions in Web Store target users accounts and data

Security researchers warn that more than 100 malicious Chrome extensions in the official Web Store are designed to steal Google OAuth2 Bearer tokens, hijack sessions (notably Telegram Web), harvest user data, and inject ads. The extensions come from five publishers across categories including Telegram clients, casino-style games, YouTube/TikTok enhancers, translation tools, and utilities, and share a centralized C2 on a Contabo VPS. The campaign is tied to a Russian MaaS operation, with several extensions capable of running at startup and remotely fetching commands. Google has been notified, but many of the extensions were still available at publication; users should audit installed extensions against the IDs published by Socket and remove any matches.

By TechLogHub
Fake Ledger Live App on Apple's App Store Drains $9.5M in Crypto
Apr 14, 2026

Fake Ledger Live App on Apple's App Store Drains $9.5M in Crypto

A fake Ledger Live Mac app on Apple’s App Store drained about $9.5 million in cryptocurrency from 50 victims in just a few days by harvesting seed phrases. Attackers moved funds across Bitcoin, Ethereum, Tron, Solana, and Ripple, then laundered them through roughly 150 KuCoin deposit addresses via the AudiA6 mixer. Three victims lost seven-figure amounts ($3.23M, $2.08M, and $1.95M); musician G. Love lost 5.9 BTC (about $430k). The counterfeit app appeared under the publisher “Leva Heal Limited” and was removed after user reports. Ledger’s legitimate Mac app is available only on its website, not in the App Store. KuCoin froze involved accounts until April 20, 2026, with possible extensions by law enforcement. This incident echoes past exploits that target app-store gaps, including a 2023 Microsoft Store case.

By TechLogHub
Microsoft rolls out fast-track to reinstate Windows hardware dev accounts
Apr 14, 2026

Microsoft rolls out fast-track to reinstate Windows hardware dev accounts

Microsoft has launched a temporary fast-track reinstatement process for Windows Hardware Dev Center developer accounts suspended over identity verification issues. Developers must open a Hardware Program support case with a clear business justification to regain access, and must still satisfy any outstanding compliance requirements once reinstated; Microsoft has not yet said how long the accelerated process will last.

By TechLogHub
5 Ways Zero Trust Maximizes Identity Security
Apr 14, 2026

5 Ways Zero Trust Maximizes Identity Security

Sponsored by Specops Software, this post argues that Zero Trust must be treated as an identity-centric strategy, not just a set of isolated controls. It outlines five practical ways Zero Trust strengthens identity security: 1) enforce least-privilege access with just-in-time and time-bound permissions; 2) implement continuous, context-aware authentication that binds identities to trusted devices; 3) limit lateral movement through granular segmentation and ongoing verification; 4) secure remote work and third-party access with identity- and device-based controls; and 5) centralize identity governance and monitoring for faster detection and response. The piece also notes that credential theft is a major breach driver (stolen credentials accounted for 22% of initial access vectors in 2025; 44.7% of breaches involve stolen credentials) and recommends starting with phishing-resistant MFA and device health checks.

By TechLogHub
European Gym giant Basic-Fit data breach affects 1 million members
Apr 13, 2026

European Gym giant Basic-Fit data breach affects 1 million members

Basic-Fit, Europe’s largest gym chain, disclosed a data breach affecting about 1 million members across the Netherlands, Belgium, Luxembourg, France, Spain, and Germany. Exposed information includes full names, addresses, emails, phone numbers, dates of birth, bank account details, and other membership data, though no IDs or passwords were accessed; franchise data was not affected. The incident was detected by monitoring systems and stopped within minutes, with an external security-led investigation underway. EU data-retention rules apply: personal data should be deleted after two years, and data in the My Basic-Fit app is accessible for one year post-termination and removed two months after uninstall.

By TechLogHub
Stolen Rockstar Games analytics data leaked by extortion gang
Apr 13, 2026

Stolen Rockstar Games analytics data leaked by extortion gang

Rockstar Games confirms a data breach linked to an Anodot security incident, with the ShinyHunters extortion group leaking 78.6 million records said to come from Rockstar’s Snowflake analytics environment; the data reportedly includes internal analytics on online services, in-game revenue and player behavior for GTA Online and Red Dead Online, plus Zendesk support metrics, while Rockstar says the access was limited and the breach has no impact on players or the organization.

By TechLogHub
Critical flaw in wolfSSL library enables forged certificate use
Apr 13, 2026

Critical flaw in wolfSSL library enables forged certificate use

Researchers disclosed a critical vulnerability in the wolfSSL SSL/TLS library (CVE-2026-5194) that allows forged certificates by weakening digest size checks during signature verification. The flaw affects several algorithms (ECDSA/ECC, DSA, ML-DSA, Ed25519, Ed448) and could let attackers impersonate trusted servers or data. wolfSSL fixed it in version 5.9.1, released April 8, 2026; organizations using wolfSSL should upgrade promptly, especially those with ECC and EdDSA/ML-DSA enabled. Some downstream vendors may have different advisories; Red Hat notes MariaDB is not affected because it uses OpenSSL. This highlights the importance of comprehensive validation across multiple surfaces and timely patching.

By TechLogHub
Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
Apr 13, 2026

Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw

Adobe has issued an emergency update for Acrobat/Reader to fix CVE-2026-34621, a zero-day that bypasses sandboxing and can execute arbitrary code via malicious PDFs, with exploits observed since December; affected products include Acrobat DC, Reader DC, and Acrobat 2024 on Windows and macOS, and users should update through Help > Check for Updates or download from Adobe’s portal, as there are no listed workarounds. The flaw was discovered by Haifei Li, and attacks have involved Russian-language oil-and-gas themed PDFs; the severity was downgraded once the vector was deemed local.

By TechLogHub
The Silent Storm: New Infostealer Hijacks Sessions, Decrypts Server-Side
Apr 13, 2026

The Silent Storm: New Infostealer Hijacks Sessions, Decrypts Server-Side

Varonis Threat Labs highlights Storm, a new infostealer that shifts credential theft to server-side decryption and automated session hijacking. Debuting in early 2026, Storm decrypts data from Chromium and Firefox-based browsers and forwards it to attacker-controlled infrastructure for silent session restoration, enabling access to SaaS and cloud services without passwords or MFA alerts. The toolkit harvests saved passwords, cookies, autofill data, tokens, crypto wallets, and more, then uses Google Refresh Tokens and SOCKS5 proxies to re-create authenticated sessions. Storm operates with dedicated infrastructure, supports tiered licensing (demo, standard, team), and runs across multiple operators; observed campaigns target Google, Facebook, Twitter/X, and crypto platforms across many countries. Indicators of compromise include the StormStealer forum handle, version Gunnar v0.0.2.0, a Windows-only C++ build, and a registration date of 12/12/25.

By TechLogHub
Critical Marimo Pre‑Authentication RCE Flaw Now Under Active Exploitation
Apr 12, 2026

Critical Marimo Pre‑Authentication RCE Flaw Now Under Active Exploitation

Critical RCE flaw CVE‑2026‑39987 in Marimo open‑source Python notebook platform was actively exploited within 10 hours of disclosure, allowing unauthenticated attackers to gain full shell access via the /terminal/ws WebSocket endpoint and exfiltrate .env credentials and SSH keys; users are urged to upgrade to v0.23.0 or block the endpoint immediately.

By TechLogHub

Showing 20 of 423 articles