TechLogHub Blog — Page 3 of 22
Insights, guides, and product strategy for builders and product teams.

Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft quietly extended the free Windows 10 Extended Security Updates (ESU) for personal devices to October 12, 2027, giving users an extra year to stay secure while they transition to Windows 11, with the update appearing in ESU documentation and an editor's note rather than a formal announcement.

Data breach exposes up to 14.2 million email logins at six ISPs
KDDI disclosed a data breach that exposed an email system used by five partner ISPs, potentially affecting up to 14.2 million email addresses and passwords. The breach was discovered on June 17, with the attacker blocked and defenses deployed afterward. It stemmed from a vulnerability in an unnamed third‑party software; some passwords were hashed or encrypted, while others may have been exposed. KDDI is notifying the affected ISPs and regulators and urging users to reset passwords and enable 2FA where available.

FBI: Russian Hackers Now Target Signal Backup Recovery Keys
The FBI and CISA warn that Russian intelligence-backed actors have escalated phishing campaigns against Signal users to steal Backup Recovery Keys, enabling attackers to access victims’ historical messages. The attackers impersonate Signal support, instruct users to enable Secure Backups and copy their recovery key, then use that key to restore backups on their own devices. An update to the March 2026 advisory notes that a stolen recovery key remains valid even if a new Signal account is created with the same phone number; users should rotate keys, never share verification codes or recovery keys, and report incidents to IC3 or CISA. The operation targets high-value individuals—government officials, military personnel, journalists, political figures, and Ukraine-related officials—and is tracked as UNC5792/UNC4221 by RIS.

Clean GitHub repo tricks AI coding agents into running malware
Mozilla 0DIN researchers reveal a proof-of-concept showing that a clean-looking GitHub repo can trigger an AI coding agent to run a hidden payload, bypassing security scanners and human review. The attack uses three innocuous elements: a normal repo with standard setup steps, a Python package that only runs after initialization, and a shell that fetches a command from a DNS TXT record. When initialization is executed, a reverse shell can open with the developer’s privileges, exposing environment variables, keys, and configs. Researchers warn that attackers could distribute such repos via job postings or tutorials and urge disclosure of full execution chains and multi-layer security testing to prevent exploitation.

Stealthy Mistic backdoor linked to ransomware access broker KongTuke
Researchers have uncovered a stealthy backdoor called Mistic (also tracked as MTLBackdoor) tied to the KongTuke/Woodgnat initial access broker. Deployed since April 2026 against sectors such as insurance, education, IT, and professional services, it often follows social engineering via Microsoft Teams and can appear after ModeloRAT. Mistic is designed for long-term, in-memory persistence, operating without writing to disk, with capabilities to manage files, execute in-memory payloads, adjust C2 polling, and self-delete via a kill switch. Security firms describe it as a modular, memory-resident tool that can load BOFs to expand functionality, illustrating the growing use of custom tools by ransomware operators.

Windows 11 KB5095093 update rolls out new Point-in-Time restore feature
Microsoft released the Windows 11 KB5095093 preview cumulative update for 24H2 and 25H2, adding a new Point-in-Time Restore feature and a suite of fixes. Point-in-Time Restore lets users roll back the entire PC to a recent restore point captured within the last 72 hours (shorter retention if storage runs out; enterprise editions can configure more frequent snapshots). The update is an optional, non-security preview, installed via Settings > Windows Update or the Microsoft Update Catalog, and it upgrades 24H2 to build 26100.8737 and 25H2 to 26100.8737. In addition to PITR, the release includes numerous improvements across Secure Boot, authentication, Widgets, networking, File Explorer, Bluetooth, WSL, display/graphics, accessibility, and more, plus a fix for Recycle Bin confirmation dialogs. Note a known issue may prevent some third-party apps from launching Microsoft Office after certain June 2026 updates; Microsoft is working on a fix.

Healthtech Firm Xsolis Suffers Data Breach Affecting 1.4 Million People
Healthtech firm Xsolis disclosed a targeted phishing breach that exposed the personal data of about 1.4 million people, including names, addresses, dates of birth, Social Security numbers, health-insurance details and medical information. Unauthorized activity was detected January 22, 2026, stemming from a phishing attack on January 20, 2026; the company has reset passwords, increased monitoring, and is offering 12 months of identity monitoring via Kroll, with no confirmed misuse to date.

Scattered Spider Members Plead Guilty to Hacking Transport for London
Two members of the Scattered Spider gang pleaded guilty to the 2024 Transport for London hack, which disrupted TfL services and caused about £29 million in damages. Thalha Jubair, 20, and Owen Flowers, 18, had initially denied involvement but changed their pleas on the first day of their Woolwich Crown Court trial. The Aug. 31–Sept. 3, 2024 breach hit TfL’s systems, including Oyster refunds data, and led to data theft. The suspects were arrested in Sept. 2025; sentencing was moved to July 16 after the guilty pleas.

The Exploit Doesn't Exist. You Can Still Prove It Works Against You
AI-driven exploitation is shrinking the window between vulnerability disclosure and weaponization to hours, outpacing traditional patching and remediation. Verizon’s 2026 DBIR shows median fix times for known-exploited vulnerabilities at 43 days with patching rates dropping, highlighting the limits of patch-based defenses. With 2025 seeing 48,185 CVEs and Mythos-era capabilities, defenders must ask not what’s vulnerable but what’s actually exploitable in their environment. Picus Security introduces TTP chaining: decompose a CVE into attacker techniques, test each step against real controls, and derive a defensible, evidence-backed verdict in hours without a live exploit. This approach complements automated pentesting by addressing off-limit assets and day-one CVEs, delivering actionable risk decisions. The post invites readers to book a demo to see how the method applies to their own environment.

LastPass confirms data breach in Klue supply chain attack
LastPass has confirmed a data breach connected to the Klue supply-chain attack, after attackers stole OAuth tokens and accessed LastPass customer data in its Salesforce environment. The company says vaults, products, and core services remained secure, but data such as customer names, phone numbers, email and physical addresses, support cases, and CRM records may have been exposed; Gong data was not accessed. The Icarus extortion group claimed the attack, which also impacted multiple other organizations. LastPass has disabled employee access to Klue, rotated the exposed tokens, and notified law enforcement. Users should beware phishing attempts and never share their master password.

WhatsApp phishing attack uses fake business docs to hack PCs
A global WhatsApp phishing campaign delivers obfuscated VBScript files masquerading as business documents to compromised contacts, prompting recipients to download a ZIP that installs ManageEngine Endpoint Central for remote access. The infection chain disables UAC and grants attackers control of the victim’s PC via Windows Script Host; the campaign has spread across Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia. Attribution is uncertain, with signs of Chinese-language usage and overlaps with ValleyRAT/Gh0st RAT infrastructure. Users should verify messages from contacts through alternate channels and scan all attachments before opening.

FortiBleed campaign used custom FortiGate sniffer to steal credentials
SOCRadar warns of FortiBleed, a large-scale campaign targeting Fortinet FortiGate firewalls since February 2026. It employs a Golang-based tool, FortigateSniffer, that abuses FortiOS’s diagnose sniffer to capture authentication data across multiple protocols, harvesting credentials and password hashes from compromised devices. The operation has affected over 430,000 FortiGate installations and has yielded VPN credentials for tens of thousands of devices, with hashes cracked on a GPU cluster. The attackers act as an initial access broker, combining credential stuffing, brute force, credential harvesting, and offline cracking; Fortinet says this involves stolen credentials rather than a new vulnerability. Defenders should audit FortiGate devices and review the listed victim IPs.

A Glimpse into the "Search Your Target" Market for Stolen Credentials
Flare researchers analyzed 470 underground posts from January 2025 to June 2026 describing a growing "search your target" service that turns infostealer‑harvested credentials into targeted queries. The service sits between raw logs and account takeover, allowing buyers to request credentials by company, domain, geography, or account type and receive filtered results in formats like URL:LOGIN:PASS, MAIL:PASS, or LOGIN:PASS. This market overlaps with but is not identical to the Initial Access Broker ecosystem, acting as a processing layer that enriches and formats data for sale. Advertised databases range from hundreds of millions to tens of billions of lines, with claimed features such as freshness, indexing, and customized enrichment, though buyers report frequent invalid or duplicate results. The report notes defenders should monitor these underground services and credential exposures to prioritize password resets, MFA enforcement, and rapid incident response. Overall, the development signals a shift toward outsourcing credential triage and targeted access preparation in the cybercrime ecosystem.

AryStinger botnet infected thousands of D-Link routers worldwide
Security researchers have disclosed AryStinger, a new botnet that has infected over 4,000 outdated D-Link routers to form a distributed network of executors for scanning, proxying, tunneling, and remote command execution. Two variants were found: a C-based version targeting legacy routers and a Go-based NAS-focused version with broader capabilities, including IP/DNS scanning and internal reconnaissance; infections are concentrated in South Korea (about 48%), followed by China (about 32%). The malware exploits CVEs 2013-3307, 2016-5681, and 2025-11837 and primarily targets D-Link DIR-850L and DIR-818LW devices. Researchers warn of DNS tampering and traffic monitoring, though attribution remains unclear. Defenders are advised to retire end-of-life routers, apply the latest firmware, change default passwords, and disable remote management.

New Prinz Eugen ransomware prioritizes recent files for encryption
Security researchers warn of Prinz Eugen, a new Go-based ransomware that targets recently modified files first and leaves no ransom note. The operators appear hands-on, leveraging legitimate RMM tools (e.g., RemotePC) and a backdoor admin account for persistence, with initial access likely from stolen RDP credentials and a manual payload (servertool.exe). It encrypts almost every file (except .prinzeugen) using ChaCha20-Poly1305 with Argon2id-derived keys, deletes originals after encryption, and is not operating as a traditional RaaS; at least five victims have been identified, with more believed affected.

Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft attributes the Mastra AI npm supply chain attack to North Korea’s Sapphire Sleet (BlueNoroff) with high confidence. Attackers hijacked an npm maintainer’s account to publish updates for over 140 @mastra packages, injecting a typosquat dependency called easy-day-js that installs a cross‑platform information stealer. The malware exfiltrates credentials, API keys, tokens, and crypto-wallet data across Windows, Linux, and macOS, using OS‑specific persistence and a PowerShell backdoor; this campaign follows prior Sapphire Sleet operations, including an April 2026 Axios npm attack.

Klue OAuth breach victim list grows as Icarus hackers claim attack
Klue confirms a security incident where OAuth tokens used to connect to Salesforce were stolen, exposing data in several customer Salesforce environments. The breach, linked to the Icarus extortion group, originated from a compromised legacy credential and was detected on June 12; Klue revoked tokens, disabled affected integrations, and engaged CrowdStrike. The company says its own platform data was not affected, but data from third-party integrations was exfiltrated from multiple customers, including Sprout Social, Jamf, Gong, Tanium, Recorded Future, and Insurity. Icarus has publicly claimed responsibility and issued extortion-style demands via its data-leak site and Session Messenger; customers are urged to stay vigilant for follow-on phishing attempts.

Hackers Exploit Unauthenticated Information Disclosure in Gravity SMTP WordPress Plugin
Threat actors are actively exploiting an unauthenticated information-disclosure vulnerability in the Gravity SMTP WordPress plugin (CVE-2026-4020), affecting all versions up to 2.1.4 on roughly 100,000 sites; a fix was released in 2.1.5 on March 17, 2026. The flaw exposes a REST API endpoint that returns a full JSON System Report, leaking API keys, OAuth tokens, email service credentials, WordPress configuration, and server details, enabling credential theft and site impersonation. Wordfence blocked more than 17 million exploit attempts, with activity peaking on June 7, 2026; indicators include GET requests to /wp-json/gravitysmtp/v1/tests/mock-data and queries like ?page=gravitysmtp-settings. Administrators should upgrade to 2.1.5 and tighten defenses, noting a related critical flaw in Avada Builder (CVE-2026-8713) fixed in 3.15.4.

Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
AI agents are emerging as real identities within enterprises, connecting to critical apps and data and often operating with broad, poorly governed access. Traditional IAM struggles to keep pace as agents create, use, and rotate credentials at machine speed, leading to high-risk exposure and governance gaps. A 2026 CSA survey commissioned by Token Security finds 82% of organizations had at least one AI agent created without security visibility and 65% suffered an AI-agent security incident, with 61% involving sensitive data. The article argues for continuous governance: comprehensive agent discovery, clear ownership and intent, least-privilege access, credential rotation, and ongoing monitoring to safely scale AI while reducing risk. It also promotes Token Security’s solutions and demos for implementing these controls.

Webinar: How Attackers Bypass MFA and How Defenders Can Respond
Upcoming live webinar on July 8, 2026, hosted by BleepingComputer, explores how attackers bypass MFA—especially through Device Code phishing that leverages legitimate Microsoft login flows—within phishing, BEC, and account takeover attacks, and how defenders can use behavioral AI to detect unusual activity, automate investigations, and reduce response times. Presented by Dan Nickolaisen of Abnormal AI and Eric Danneker of Novant Health.
Showing 20 of 423 articles


