TechLogHub Blog — Page 19 of 22

Insights, guides, and product strategy for builders and product teams.

Showing 20 of 423 articles
Russia arrests suspected owner of LeakBase cyber‑crime forum
Mar 26, 2026

Russia arrests suspected owner of LeakBase cyber‑crime forum

Russian police arrested the suspected owner of LeakBase, a major cybercrime forum used for buying and selling stolen data and hacking tools, following its seizure by the FBI and international law‑enforcement operation “Operation Leak” that shut down the platform in March 2026.

By TechLogHub
Armenian suspect extradited to the U.S. for alleged role in RedLine infostealer malware operations
Mar 26, 2026

Armenian suspect extradited to the U.S. for alleged role in RedLine infostealer malware operations

Armenian suspect Hambardzum Minasyan has been extradited to the U.S. and charged with running the RedLine infostealer malware, a major cyber‑crime platform that steals data from corporate systems. He allegedly set up virtual servers, domains, cryptocurrency accounts and file‑sharing sites used by affiliates to distribute the malware. Minasyan faces charges including access‑device fraud, computer‑fraud and abuse, money laundering conspiracy, and could receive up to 30 years in prison. U.S. authorities have also targeted Russian developer Maxim Alexandrovich Rudometov, who may face a maximum of 35 years. The U.S. Department of State has offered up to $10 million for tips on state‑sponsored hackers linked to RedLine. The Dutch police seized RedLine’s infrastructure in 2024 as part of Operation Magnus.

By TechLogHub
GitHub adds AI‑powered bug detection to expand security coverage
Mar 25, 2026

GitHub adds AI‑powered bug detection to expand security coverage

GitHub is adding AI‑powered scanning to its Code Security tool, creating a hybrid model that combines traditional CodeQL analysis with broader coverage for languages like Shell/Bash, Dockerfiles, Terraform and PHP. The new AI detections aim to uncover security issues that static analysis alone misses, and will be available in public preview early Q2 2026. This move reflects a shift toward embedding AI‑augmented security directly into the development workflow, supported by features such as Copilot Autofix which speeds up issue resolution.

By TechLogHub
PolyShell Attacks Target 56 % of All Vulnerable Magento Stores
Mar 25, 2026

PolyShell Attacks Target 56 % of All Vulnerable Magento Stores

PolyShell attacks are now exploiting 56% of all vulnerable Magento Open Source and Adobe Commerce stores, with hackers launching attacks just days after the flaw was disclosed. The vulnerability lies in Magento’s REST API, allowing polyglot file uploads that can lead to remote code execution or XSS if server settings permit. Adobe released a patch (2.4.9‑beta1) on March 10, but it remains unavailable for stable releases. Sansec has identified active attack IPs and revealed that some attackers are also deploying a WebRTC-based payment card skimmer capable of bypassing strict CSP controls, which was detected on a major automotive e‑commerce site. Defenders are urged to apply the latest patches and monitor for indicators of compromise.

By TechLogHub
Bubble AI App Builder Abused to Steal Microsoft Account Credentials
Mar 25, 2026

Bubble AI App Builder Abused to Steal Microsoft Account Credentials

Threat actors are using the no‑code AI app builder Bubble to create and host malicious web apps that mimic Microsoft login pages, allowing them to steal Microsoft 365 credentials. Because these sites run on Bubble’s trusted *.bubble.io domain, email security tools don’t flag the links, letting users access the phishing page. The generated apps contain large JavaScript bundles and Shadow DOM structures that evade automated analysis, making it hard for defenders to detect the malicious intent. Kaspersky warns that this technique is likely to spread through phishing‑as‑a‑service kits, increasing the stealth of attacks against Microsoft accounts.

By TechLogHub
New Torg Grabber Infostealer Targets 728 Crypto Wallets
Mar 25, 2026

New Torg Grabber Infostealer Targets 728 Crypto Wallets

New infostealer malware “Torg Grabber” is actively stealing data from 850 browser extensions, targeting 728 crypto wallet add‑ons (including MetaMask, TrustWallet, Coinbase, Binance, etc.) and also capturing credentials from 103 password manager/2FA extensions. It spreads via a ClickFix clipboard hijack that runs malicious PowerShell, uses evolving exfiltration methods (now HTTPS through Cloudflare), anti‑analysis techniques, and can bypass Chrome’s App‑Bound Encryption. The malware profiles the host, takes screenshots, steals desktop files, and can execute shellcode from its C2. Researchers note rapid development with new samples and domains weekly.

By TechLogHub
Citrix urges admins to patch NetScaler flaws as soon as possible
Mar 25, 2026

Citrix urges admins to patch NetScaler flaws as soon as possible

Citrix has released patches for two critical vulnerabilities (CVE‑2026‑3055 and CVE‑2026‑4368) affecting NetScaler ADC and Gateway appliances, which could allow remote attackers to read memory or cause session mix‑ups. The flaws are similar to the previously exploited CitrixBleed variants, raising concerns that exploit code may soon appear in the wild. Citrix urges customers to apply the updates immediately and provides guidance for identifying affected instances. Over 30,000 NetScaler ADC and more than 2,300 Gateway devices are exposed online, but it is unclear how many remain vulnerable.

By TechLogHub
Paid AI Accounts Are Now a Hot Underground Commodity
Mar 25, 2026

Paid AI Accounts Are Now a Hot Underground Commodity

Paid AI platform accounts are now a thriving underground commodity, with fraud‑oriented forums and Telegram groups selling discounted or bundled subscriptions to services like ChatGPT, Claude, Microsoft Copilot, Perplexity, and API keys. Threat actors acquire these accounts through exposed credentials, account takeovers, bulk creation, trial abuse, or resold subscriptions, often targeting users in sanctioned regions who face payment restrictions. The resale market offers cheaper, “no‑limits” access that fuels large‑scale phishing, social engineering, and automated fraud campaigns. Organizations can mitigate risk by enforcing MFA, monitoring anomalous usage, rotating API keys, restricting sensitive data sharing, and staying alert to underground listings.

By TechLogHub
Kali Linux 2026.1 Released with 8 New Tools and a New BackTrack Mode
Mar 25, 2026

Kali Linux 2026.1 Released with 8 New Tools and a New BackTrack Mode

Kali Linux 2026.1 has been released, bringing 25 new packages, 183 updates, and a kernel upgrade to 6.18. The update introduces eight notable tools—AdaptixC2, Atomic-Operator, Fluxion, GEF, MetasploitMCP, SSTImap, WPProbe, and XSStrike—alongside a refreshed theme with new wallpapers and an improved installer interface. A new “BackTrack mode” for Kali Undercover lets users emulate the classic BackTrack look, while NetHunter receives bug fixes and permission checks. Users can upgrade via apt or download fresh ISO images; instructions are provided for WSL 2 support and post‑upgrade verification.

By TechLogHub
TP‑Link Warns Users to Patch Critical Router Authentication Bypass Flaw
Mar 25, 2026

TP‑Link Warns Users to Patch Critical Router Authentication Bypass Flaw

TP‑Link has released firmware updates for its Archer NX series (NX200, NX210, NX500, NX600) to fix a critical authentication bypass flaw (CVE‑2025‑15517) that lets attackers upload malicious firmware and change settings without credentials. The update also removes a hardcoded key (CVE‑2025‑15605), patches two command‑injection bugs (CVE‑2025‑15518/15519), and the company urges users to install the new firmware immediately, warning that failure to do so leaves devices vulnerable.

By TechLogHub
Russian Botnet Manager Sentenced to 2 Years Over BitPaymer Ransomware Attacks
Mar 25, 2026

Russian Botnet Manager Sentenced to 2 Years Over BitPaymer Ransomware Attacks

Russian cybercriminal Ilya Angelov, who ran the “Mario Kart” botnet used to launch BitPaymer ransomware against 72 U.S. companies, pleaded guilty and was sentenced to two years in prison after traveling to the United States. The botnet distributed malware via massive spam campaigns, infecting thousands of computers daily between 2017‑2021 and selling access to other criminal groups, resulting in over $14 million in extortion payments. Angelov’s case follows similar prosecutions of Russian cybercriminals involved in ransomware operations.

By TechLogHub
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
Mar 24, 2026

PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug

PTC has issued an emergency alert for a critical remote‑code execution flaw (CVE‑2026‑4681) affecting its Windchill and FlexPLM product lifecycle management software, which could be exploited via deserialization of trusted data. German federal police have dispatched officers to notify affected companies, underscoring the urgency. No patch is yet available; PTC recommends applying an Apache/IIS rule to block access to the vulnerable servlet path, prioritizing internet‑facing instances, and temporarily disconnecting or shutting down services if mitigation isn’t possible. The vendor has released indicators of compromise and detection guidance but reports no confirmed exploitation so far, though credible evidence suggests imminent threat from a third‑party group.

By TechLogHub
LiteLLM PyPI Package Compromised in TeamPCP Supply‑Chain Attack
Mar 24, 2026

LiteLLM PyPI Package Compromised in TeamPCP Supply‑Chain Attack

TeamPCP has compromised the popular LiteLLM Python package on PyPI, pushing malicious versions 1.82.7 and 1.82.8 that inject an infostealer into the library’s import process. The payload harvests credentials (SSH keys, cloud tokens, Kubernetes secrets, crypto wallets, etc.), attempts lateral movement in Kubernetes clusters, installs a persistent systemd backdoor, and exfiltrates data to attacker‑controlled domains. Roughly 500,000 devices are reported infected. Both malicious releases have been removed; users should check for affected versions, rotate all credentials, inspect for persistence artifacts, review Kubernetes pods, and monitor outbound traffic to known malicious endpoints.

By TechLogHub
Firefox now has a free built-in VPN with 50GB monthly data limit
Mar 24, 2026

Firefox now has a free built-in VPN with 50GB monthly data limit

Firefox 149 introduces a free built‑in VPN that lets users hide their location and IP address for up to 50 GB of browser traffic each month. The VPN is activated via a toggle in the browser, can be limited to specific sites, and only routes Firefox traffic—not system-wide traffic like Mozilla’s commercial VPN. It’s available initially in the U.S., UK, Germany, and France, with notifications when the limit approaches. Alongside the VPN, Firefox 149 adds Split View for side‑by‑side tabs, automatically blocks malicious sites through SafeBrowsing, and patches over 40 security vulnerabilities.

By TechLogHub
Microsoft fixes bug causing Classic Outlook sync issues with Gmail
Mar 24, 2026

Microsoft fixes bug causing Classic Outlook sync issues with Gmail

Microsoft has resolved a bug that caused Gmail and Yahoo accounts to fail syncing in classic Outlook, generating error codes 0x800CCC0F and 0x80070057. The issue was fixed on February 26, 2026, though some users may still experience problems until their OAuth token expires; a temporary workaround is to delete the relevant registry entries for the affected email address.

By TechLogHub
Dutch Ministry of Finance discloses cyber breach affecting employees
Mar 24, 2026

Dutch Ministry of Finance discloses cyber breach affecting employees

Dutch Ministry of Finance confirmed a cyberattack on March 19 that breached some internal systems, affecting certain employees but not critical tax or customs services. The breach was detected by a third party and investigated, with access blocked; details on the number of affected staff or data stolen remain undisclosed.

By TechLogHub
Mazda exposes employee and partner data in security breach
Mar 23, 2026

Mazda exposes employee and partner data in security breach

Mazda Motor Corporation announced a security breach that exposed data for 692 employees and business partners, including user IDs, full names, email addresses, company names, and partner IDs. The incident involved an unauthorized access to a warehouse management system used for parts from Thailand; no customer data was affected. Mazda promptly reported the breach to Japan’s Personal Information Protection Commission, implemented additional security measures, and is monitoring for potential phishing or scam risks. No ransomware group has publicly claimed responsibility, though Clop previously listed Mazda on its leak site. The company advises impacted individuals to remain vigilant.

By TechLogHub
Tycoon2FA phishing platform returns after recent police disruption
Mar 23, 2026

Tycoon2FA phishing platform returns after recent police disruption

Tycoon2FA, a phishing‑as‑a‑service platform targeting Microsoft 365 and Gmail accounts with two‑factor authentication bypassing techniques, was disrupted by Europol and Microsoft on March 4, 2026, involving the seizure of 330 domains. The takedown temporarily reduced daily campaign volumes to about 25% of pre‑disruption levels, but within days the platform returned to its previous activity level, using largely unchanged tactics and infrastructure. CrowdStrike notes that some old infrastructure remained active while new phishing domains and IPs were quickly registered after the law enforcement operation, allowing cybercriminals to recover and continue their operations. The disruption was short‑lived due to limited arrests or physical seizures, underscoring the resilience of phishing‑as‑a‑service operators.

By TechLogHub
TeamPCP Deploys Iran‑Targeted Wiper in Kubernetes Attacks
Mar 23, 2026

TeamPCP Deploys Iran‑Targeted Wiper in Kubernetes Attacks

TeamPCP has launched a new attack targeting Kubernetes clusters and Iranian systems, deploying a malicious script that wipes machines when it detects Iran’s timezone or locale. The campaign uses the same command‑and‑control, backdoor code, and drop path as seen in the CanisterWorm incidents, but adds a geopolitically targeted destructive payload. In Kubernetes environments, it installs a DaemonSet that mounts the host filesystem and runs Alpine containers named “kamikaze” to delete all top‑level directories and reboot the host. On non‑Kubernetes Iranian machines, the malware deletes all files, including system data, using rm -rf with no‑preserve‑root and attempts passwordless sudo if root privileges are unavailable. When conditions aren’t met, the malware exits harmlessly. Recent variants also use SSH propagation, parsing authentication logs for credentials, and stolen private keys to spread, with indicators such as outbound SSH connections with “StrictHostKeyChecking+no” and privileged Alpine containers via an unauthenticated Docker API. The attack reflects a growing trend of geopolitically targeted wipers that leverage Kubernetes lateral movement and advanced detection techniques.

By TechLogHub
Crunchyroll Investigates Massive Data Breach: 6.8 Million Users’ Personal Info Stolen
Mar 23, 2026

Crunchyroll Investigates Massive Data Breach: 6.8 Million Users’ Personal Info Stolen

Crunchyroll is investigating a breach after hackers claimed to steal personal data from about 6.8 million users. The attackers allegedly compromised an employee of Telus International, a BPO company, by infecting their computer and accessing Crunchyroll’s Okta SSO account. They used the credentials to download support ticket records from Zendesk, revealing user names, emails, IPs, locations, and ticket contents—some credit card details were included only when customers shared them in tickets. The breach reportedly lasted 24 hours, and the hackers sent extortion demands of $5 million, but Crunchyroll did not respond. BPOs are increasingly targeted because they handle customer support and internal authentication for multiple companies.

By TechLogHub

Showing 20 of 423 articles