TechLogHub Blog — Page 17 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
US warns of Iranian hackers targeting critical infrastructure PLCs
Apr 7, 2026

US warns of Iranian hackers targeting critical infrastructure PLCs

Iranian-linked hackers are attacking internet‑exposed Rockwell/Allen‑Bradley programmable logic controllers (PLCs) across U.S. critical infrastructure sectors—including government services, water and wastewater systems, and energy—causing financial losses and operational disruptions since March 2026. A joint advisory from the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command warns that these attacks involve extracting PLC project files and manipulating HMI/SCADA displays. The agencies recommend disconnecting PLCs from the internet or securing them with firewalls, monitoring logs for compromise indicators, implementing multi‑factor authentication, updating firmware, disabling unused services, and checking for suspicious traffic on OT ports. Previous similar threats, such as the CyberAv3ngers group exploiting Unitronics devices in 2023‑24, underscore the ongoing risk to critical infrastructure.

By TechLogHub
Max severity Flowise RCE vulnerability now exploited in attacks
Apr 7, 2026

Max severity Flowise RCE vulnerability now exploited in attacks

Hackers are actively exploiting CVE‑2025‑59528, a critical remote code execution flaw in the open‑source Flowise platform that allows arbitrary JavaScript injection via its CustomMCP node. The vulnerability, disclosed last September, can execute commands and access the file system. While Flowise has patched the issue in version 3.0.6 (and newer 3.1.1), many of the estimated 12‑15k publicly exposed instances remain vulnerable. Security researchers warn that attacks are already underway, urging users to upgrade immediately or remove public exposure.

By TechLogHub
Authorities Shut Down APT28’s Router‑DNS Hijack That Stole Microsoft 365 Logins
Apr 7, 2026

Authorities Shut Down APT28’s Router‑DNS Hijack That Stole Microsoft 365 Logins

Authorities have disrupted the FrostArmada DNS hijacking campaign by APT28, a Russian threat group linked to GRU, which compromised MikroTik and TP‑Link routers in 18,000 devices across 120 countries to steal Microsoft 365 credentials. Law enforcement, Microsoft, Black Lotus Labs, Lumen, and government agencies removed the malicious infrastructure and provided indicators of compromise and mitigation guidance to prevent future attacks.

By TechLogHub
Why Your Automated Pentesting Tool Just Hit a Wall
Apr 7, 2026

Why Your Automated Pentesting Tool Just Hit a Wall

Automated penetration testing tools often start strong, revealing new vulnerabilities and attack paths in their first run, but by the fourth or fifth execution they hit a “Proof‑of‑Concept Cliff”: the tool’s fixed scope is exhausted, producing stale findings that give a false sense of security. This gap—between what organizations actually validate and what is reported as validated—shows that automated pentesting alone cannot fully assess an organization’s attack surface. Breach & Attack Simulation (BAS) differs by running thousands of independent, atomic tests to verify the effectiveness of defensive controls across the MITRE ATT&CK framework, whereas automated pentesting chains vulnerabilities like a real attacker would. The article highlights six layers of an attack surface—network and endpoint controls, detection and response stack, infrastructure and application paths, identity and privilege, cloud and container environments, and AI technology—that automated tools typically miss or only partially cover. To bridge the validation gap, organizations should evaluate tools on three diagnostic questions: coverage of each surface, differentiation between exploitable and theoretical vulnerabilities using live control data, and normalization of findings into a single prioritized action list. The conclusion urges shifting from relying solely on automated pentesting to integrating BAS and other complementary methods to achieve comprehensive, actionable security validation.

By TechLogHub
Microsoft removes Support and Recovery Assistant from Windows
Apr 6, 2026

Microsoft removes Support and Recovery Assistant from Windows

Microsoft has removed the Support and Recovery Assistant (SaRA) from all supported Windows updates as of March 10, 2026. SaRA was a free command‑line tool that automated diagnostics for Office, Microsoft 365, Outlook, Teams, and Windows. Administrators are urged to switch to the newer Get Help utility, which offers similar troubleshooting capabilities with enhanced security. The deprecation is part of a broader trend of retiring legacy services such as Authenticator’s password autofill, Publisher, and Lens PDF scanner.

By TechLogHub
Why Simple Breach Monitoring Is No Longer Enough
Apr 6, 2026

Why Simple Breach Monitoring Is No Longer Enough

Stolen credentials remain a top security risk, yet many enterprises rely on simple checkbox tools that focus on data breaches rather than infostealers, leaving gaps when attackers use session cookies to bypass MFA and EDR. A survey shows only 32% of firms have dedicated monitoring, with most checking monthly or not at all. Lunar’s free breach‑monitoring platform continuously ingests breaches, stealer logs, combolists, and dark‑web chatter, automates alerts, and integrates with SIEM/SOAR to reset credentials and block accounts immediately. By treating breach monitoring as an ongoing program rather than a one‑off check, organizations can gain real visibility into compromised credentials, understand the full scope of infostealer theft (including cookies and SaaS access), and respond faster—essential in 2026 when infostealers move quickly and at scale.

By TechLogHub
New FortiClient EMS flaw exploited in attacks, emergency patch released
Apr 5, 2026

New FortiClient EMS flaw exploited in attacks, emergency patch released

Fortinet has issued an emergency patch for a critical FortiClient Enterprise Management Server (EMS) flaw (CVE‑2026‑35616) that is actively being exploited in the wild, allowing unauthenticated attackers to execute arbitrary code via crafted requests. The vulnerability affects EMS versions 7.4.5 and 7.4.6 and can be mitigated by installing the provided hotfixes or upgrading to version 7.4.7; FortiClient EMS 7.2 is not impacted. The flaw was discovered by Defused Cyber, who also reported a related earlier exploit (CVE‑2026‑21643). Fortinet urges all affected customers to apply the fix immediately to prevent compromise.

By TechLogHub
Hackers Exploit React2Shell in Automated Credential Theft Campaign
Apr 5, 2026

Hackers Exploit React2Shell in Automated Credential Theft Campaign

Hackers are using the React2Shell (CVE‑2025-55182) flaw in vulnerable Next.js apps to launch a large‑scale automated credential theft operation, compromising at least 766 hosts across multiple cloud providers. The attackers deploy a script that harvests environment variables, API keys, database and cloud credentials, SSH keys, Kubernetes tokens, Docker data, command history, and process information, exfiltrating it via HTTP requests to a C2 server powered by the Nexus Listener framework. Cisco Talos attributes the activity to threat cluster UAT‑10608 and warns that stolen secrets enable cloud account takeovers, lateral movement, supply chain attacks, and regulatory violations. Immediate remediation includes patching React2Shell, rotating credentials, enforcing IMDSv2, enabling secret scanning, deploying WAF/RASP for Next.js, and applying least‑privilege controls.

By TechLogHub
Axios npm hack used fake Teams error fix to hijack maintainer account
Apr 4, 2026

Axios npm hack used fake Teams error fix to hijack maintainer account

Axios, a popular Node.js HTTP client, suffered a supply‑chain attack when North Korean threat actors (UNC1069) compromised a maintainer’s account via social engineering. They created fake Slack and Microsoft Teams workspaces that prompted the maintainer to install malicious “updates,” giving attackers remote access to npm credentials. Two infected Axios releases (1.14.1 and 0.30.4) were published for three hours, injecting a dependency that deployed a RAT on macOS, Windows, and Linux. The maintainers wiped affected systems, reset credentials, and are tightening controls. Other Node.js package maintainers also reported similar attacks, highlighting a coordinated campaign targeting high‑impact open‑source projects.

By TechLogHub
Device code phishing attacks surge 37x as new kits spread online
Apr 4, 2026

Device code phishing attacks surge 37x as new kits spread online

Device code phishing attacks, which exploit OAuth 2.0’s Device Authorization Grant to hijack accounts, have surged more than 37 times this year. Researchers at Push Security noted a 15x increase in March and now a 37.5x rise, driven largely by the EvilTokens kit that offers phishing-as-a-service. Multiple other kits—such as VENOM, SHAREFILE, CLURE, LINKID, AUTHOV, DOCUPOLL, FLOW_TOKEN, PAPRIKA, DCSTATUS, and DOLCE—also use realistic SaaS-themed lures and cloud hosting to facilitate attacks. To mitigate these threats, users should disable the device code flow when unnecessary, enforce conditional access policies, monitor logs for unusual authentication events, and remain vigilant against new phishing kits.

By TechLogHub
LinkedIn secretly scans for 6,000+ Chrome extensions and collects device data
Apr 3, 2026

LinkedIn secretly scans for 6,000+ Chrome extensions and collects device data

LinkedIn’s website uses hidden JavaScript to scan visitors’ browsers for over 6,000 Chrome extensions and collect device data such as CPU cores, memory, screen resolution, timezone, battery status, and more. The “BrowserGate” report claims LinkedIn links this information to user profiles, potentially gathering sensitive personal and corporate data and using it to target competitors or enforce policy violations. While LinkedIn denies misuse of the data, acknowledging the scans are for detecting extensions that violate its terms, independent testing confirmed the script’s activity and scope. This incident highlights broader concerns about aggressive fingerprinting practices by major web platforms.

By TechLogHub
Hims & Hers Warns of Data Breach After Zendesk Support Ticket Leak
Apr 3, 2026

Hims & Hers Warns of Data Breach After Zendesk Support Ticket Leak

Hims & Hers Health announced a data breach in early February 2026 when attackers accessed customer support tickets via its third‑party Zendesk platform, likely through compromised Okta SSO accounts used by the ShinyHunters extortion gang. The stolen tickets contained personal information such as names and contact details but no medical records were exposed. Hims & Hers is offering 12 months of free credit monitoring and urges customers to watch for phishing attempts and monitor their accounts.

By TechLogHub
Die Linke German political party confirms data stolen by Qilin ransomware
Apr 3, 2026

Die Linke German political party confirms data stolen by Qilin ransomware

Qilin ransomware gang has stolen data from Germany’s Die Linke party, threatening to leak sensitive internal and employee information while confirming the membership database was untouched; the party has reported the breach to authorities, filed a police complaint, and is working with IT experts to restore systems amid concerns that the attack may be part of hybrid warfare.

By TechLogHub
Evolution of Ransomware: Multi‑Extortion Ransomware Attacks
Apr 3, 2026

Evolution of Ransomware: Multi‑Extortion Ransomware Attacks

Ransomware attacks are evolving from simple file encryption to multi‑extortion tactics that first exfiltrate sensitive data and then threaten public release, forcing victims to pay or face further pressure such as contacting customers directly. Recent high‑profile incidents—like the University of Mississippi Medical Center’s shutdown of clinics and BridgePay’s payment outage—illustrate how ransomware now disrupts healthcare, finance, and manufacturing operations worldwide. With 124 active groups and AI tools lowering entry barriers, traditional perimeter defenses are inadequate. Penta Security’s D.AMO platform counters every stage: it encrypts files at the folder level, blocks malicious processes via strict access control, and provides independent backup recovery, ensuring that even if data is stolen it remains unreadable and organizations can restore operations without negotiating with attackers.

By TechLogHub
Microsoft Still Working to Fix Exchange Online Mailbox Access Issues
Apr 3, 2026

Microsoft Still Working to Fix Exchange Online Mailbox Access Issues

Microsoft is still investigating and working to fix intermittent Exchange Online mailbox access issues that have affected Outlook mobile and macOS users for weeks, following a recent service outage linked to a newly introduced virtual account; the company has restarted the Notification Broker service on affected infrastructure while continuing root‑cause analysis.

By TechLogHub
Former Engineer Pleads Guilty After Locking Out 254 Windows Servers in Extortion Plot
Apr 3, 2026

Former Engineer Pleads Guilty After Locking Out 254 Windows Servers in Extortion Plot

Former core infrastructure engineer Daniel Rhyne pleaded guilty to hacking an industrial company’s network, locking out 254 servers and 3,284 workstations by changing admin passwords and deleting domain accounts, then sending ransom emails demanding $750,000 in Bitcoin; he faces up to 15 years in prison.

By TechLogHub
CERT‑EU: European Commission hack exposes data of 30 EU entities
Apr 3, 2026

CERT‑EU: European Commission hack exposes data of 30 EU entities

European Union CERT‑EU has identified the TeamPCP threat group as responsible for a major cloud hack that compromised the European Commission’s Amazon Web Services environment, exposing data from at least 29 other EU entities and 42 internal Commission clients. The breach began on March 10 when TeamPCP used a stolen AWS API key—originating from a Trivy supply‑chain attack—to gain management access to the Commission’s accounts. They then leveraged tools such as TruffleHog to locate additional secrets, added new credentials to existing users to evade detection, and exfiltrated tens of thousands of files containing personal information, usernames, email addresses, and outbound email content. The stolen dataset was released by the extortion group ShinyHunters on the dark web in a 90 GB archive (340 GB uncompressed). No websites were taken offline or tampered with, and no lateral movement to other Commission AWS accounts has been detected. CERT‑EU is continuing its analysis and has notified relevant data protection authorities while maintaining direct communication with affected entities.

By TechLogHub
Claude Code Leak Used to Push Infostealer Malware on GitHub
Apr 2, 2026

Claude Code Leak Used to Push Infostealer Malware on GitHub

Threat actors exploited an accidental leak of Claude Code’s full client‑side source code, creating fake GitHub repositories that entice users to download a malicious archive containing the Vidar infostealer and GhostSocks traffic proxy. The repositories are heavily promoted via search engine optimization, attracting many downloads, and may evolve with additional payloads. This incident highlights how public code leaks can be weaponized for malware distribution on platforms like GitHub.

By TechLogHub
Drift loses $280 million as hackers seize its security council powers
Apr 2, 2026

Drift loses $280 million as hackers seize its security council powers

Drift Protocol suffered a $280 million loss after hackers hijacked its Security Council by using durable nonce accounts and pre‑signed transactions to gain admin control, add malicious assets, remove withdrawal limits, and drain funds. The attack occurred between March 23–30 and was executed on April 1. Drift confirmed no smart contract vulnerabilities or seed phrase compromise, issued a warning to users, froze all protocol functions, and is collaborating with security firms, exchanges, and law enforcement to recover the stolen assets.

By TechLogHub
Residential proxies evaded IP reputation checks in 78% of 4 billion sessions
Apr 2, 2026

Residential proxies evaded IP reputation checks in 78% of 4 billion sessions

Researchers found that residential proxies used for malicious traffic evade IP‑reputation checks in 78 % of 4 billion sessions, challenging the assumption that attackers can be identified by their source location. GreyNoise’s analysis shows most of these proxy IPs are short‑lived—often active for less than a month—and rotate quickly, preventing defense systems from cataloging them. About 39 % of sessions originate from home networks and 78 % remain invisible to reputation feeds. The proxies come from diverse ISPs (683 providers) and mainly perform network scanning rather than exploits, with only 0.1 % involved in real attacks. They are sourced largely from China, India, and Brazil, and stem from two ecosystems: IoT botnets and infected computers that use free VPNs or ad‑blocker SDKs. Even after Google disrupted the large IPIDEA network, other providers quickly filled the gap, showing the resilience of this proxy ecosystem. GreyNoise recommends moving beyond IP reputation to focus on behavioral detection—monitoring sequential probing from rotating IPs, blocking illegitimate protocols like SMB, and tracking device fingerprints that survive IP changes.

By TechLogHub

Showing 20 of 423 articles