TechLogHub Blog — Page 9 of 22
Insights, guides, and product strategy for builders and product teams.

Laravel Lang packages hijacked to deploy credential-stealing malware
A supply-chain attack hit Laravel Lang localization packages by hijacking GitHub tags to point to malicious commits, affecting multiple releases across laravel-lang/lang, http-statuses, attributes, and possibly actions. Attackers rewrote existing tags (not code) to a malicious fork, enabling legitimate-looking releases to deliver malware via Composer. The payload acts as a dropper that fetches a second-stage credential-stealer from a C2 domain, harvesting cloud credentials, tokens, SSH keys, Git credentials, and other secrets across Linux, macOS, and Windows (including a Windows infostealer named DebugElevator). Packagist quickly removed the malicious versions; developers are advised to audit installed versions, rotate exposed credentials, search for indicators of compromise, and check for outbound connections to flipboxstudio.info. The Laravel Lang project itself was not compromised.

Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming Auth Codes
Italian authorities dismantled the CINEMAGOAL piracy network in the nationwide operation “Tutto Chiaro,” seizing servers in France and Germany, identifying end users, and disrupting a stealth app that stole streaming authentication codes for Netflix, Disney+, Sky, DAZN, Spotify, and more. The scheme, run by a network of over 70 resellers and backed by crypto payments and fake IDs, is estimated to have caused about €300 million in unpaid subscription revenue; the investigation is ongoing.

Netherlands Seizes 800 Servers Linked to Hosting Firm Behind Cyberattacks and Disinformation
Dutch authorities seized 800 servers and arrested two men tied to Stark Industries, a hosting firm accused of enabling cyberattacks, information manipulation, and disruption campaigns on behalf of sanctioned Russian and Belarusian entities. Investigators say Stark Industries operated through WorkTitans B.V. (THE.Hosting) with support from Mirhosting, providing hosting, colocation, and connectivity to route traffic for these operations. The EU had sanctioned Stark Industries on May 20, 2025. Raids targeted data centers in Dronten and Schiphol-Rijk, with searches in Enschede and Almere as part of the probe.

Former US execs plead guilty to aiding tech support scammers
Two former executives of CA Cloud Attribution pleaded guilty to misprision of a felony for aiding a years-long tech support fraud that used deceptive pop-ups and remote access to steal from victims worldwide. They ran the C.A. Cloud business (2017–2022) and a Tunisia call center (2016–2022), allegedly helping fraudsters by marketing services and using rotating phone numbers; sentencing is June 16, with a maximum penalty of three years in prison and a $250,000 fine.

Google Exposes Unfixed Chromium Flaw That Keeps JavaScript Running in the Background
Google accidentally published details of an unfixed Chromium flaw that lets a background Service Worker keep JavaScript running after the browser is closed, enabling remote code execution on visiting devices. Reported by security researcher Lyra Rebane and known in Chromium Issue Tracker since 2022, the vulnerability could be exploited to create botnets or drive DDoS attacks across all Chromium-based browsers. Despite prior claims of a fix, Rebane demonstrated the issue persists in recent builds, and Google's exposure has heightened risk, with an emergency patch anticipated.

Apple blocked over $11 billion in App Store fraud in six years
Apple says it blocked over $11 billion in fraudulent App Store transactions across six years, with more than $2.2 billion blocked in 2025 alone. In 2025, it rejected over 2 million problematic app submissions, blocked 1.1 billion fraudulent account creations, terminated 193,000 developer accounts, and deactivated about 40.4 million user accounts suspected of fraud. The company also stopped 5.4 million stolen credit cards from being used, and removed or blocked numerous deceptive apps and reviews, including 195 million fraudulent ratings from 1.3 billion processed. Apple attributes these results to a mix of human review and machine learning, noting 850 million weekly App Store visits across 175 storefronts.

Discord Rolls Out End-to-End Encryption for Voice and Video Calls
Discord now provides end-to-end encryption by default for all voice and video calls across platforms, covering DMs, group DMs, voice channels, and Go Live streams, with stage channels excluded. Built on the extended DAVE protocol after extensive testing, there is no opt-in required and no plans to encrypt text-based messages.

Microsoft testing adjustable taskbar, Start menu in Windows 11
Microsoft tests Windows 11 Insider Preview Build 26300.8493, bringing back a resizable taskbar that can be placed on any screen edge and use smaller icons, plus Start menu customization (toggle recommendations, adjust size, keep recently installed apps, and hide your name/profile). The release also introduces a faster, dark-mode Run dialog (with the Browse button removed) and signals broader UI tweaks, reduced notifications, simpler settings, and improved search to enhance overall performance.

Leaked Shai-Hulud malware fuels new npm infostealer campaign
Leaked Shai-Hulud malware is driving a new npm infostealer campaign, with four typosquatted packages (chalk-tempalte, @deadcode09284814/axios-util, axois-utils, color-style-utils) that exfiltrate credentials, secrets, and crypto wallet data; one also acts as a DDoS bot. Chalk-tempalte appears to be a Shai-Hulud clone deployed by a copycat actor (not TeamPCP). Stolen data is sent to a C2 server at 87e0bbc636999b.lhr.life. Researchers urge removing infected packages and rotating credentials/API keys; the four packages have about 2,678 downloads.

Grafana Breach Caused by Missed Token Rotation After TanStack Attack
Grafana says a data breach occurred when a single GitHub workflow token was missed during rotation after the TanStack npm supply-chain attack tied to the Shai-Hulud campaign, allowing attackers to access private repositories. The malicious TanStack package exfiltrated tokens after Grafana’s CI/CD pulled it, and although Grafana rotated many tokens, one token remained compromised. The intruder also downloaded some operational details, including business contact information, but Grafana asserts no customer production data or systems were affected and the codebase wasn’t modified. No action is needed by users unless new evidence changes the assessment, in which case Grafana will notify affected customers.

Webinar: The hidden bottlenecks in network incident response
BleepingComputer will host a live webinar on June 2, 2026, titled “From alert to resolution: Fixing the gaps in network incident response,” featuring Edgar Ortiz from Tines. The session explores how high alert volumes and manual cross-system workflows slow incident response, and how AI-assisted workflows and automation can streamline triage, enrichment, routing, and resolution across monitoring, identity, and security tools. Attendees will learn to automatically enrich alerts with network, identity, and threat context, prioritize and route incidents without manual intervention, and move from fragmented response to coordinated resolution. Register now to secure your spot.

Microsoft confirms patching issues in restricted Windows networks
Microsoft confirms a Windows Update issue in restricted networks (air‑gapped or tightly firewalled) after January 2026 optional non‑security previews. Affected devices may download the February 2026 security update but then cannot download March and later updates, displaying error 0x80010002. The problem stems from changed download timeout behavior and does not affect update installation. Microsoft recommends a workaround using Known Issue Rollback (KIR) via Group Policy, with specific KB rollbacks for Windows 11 26H1 and for Windows 11 24H2/25H2 and Windows Server 2025, plus a restart to apply the policy and guidance on deployment.

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
Tycoon2FA, a well-known phishing toolkit, has added device-code phishing to its arsenal, using Trustifi tracking URLs to hijack Microsoft 365 accounts via the OAuth device login flow. After an international police disruption in March, the operation rebuilt its infrastructure and returned to normal activity with added obfuscation. In late April, Tycoon2FA campaigns leveraged the device authorization grant to gain OAuth tokens, granting attackers access to victims’ emails, calendars, and cloud storage. Researchers warn that device-code phishing is surging and recommend defenses such as disabling the device-code flow when not needed, restricting OAuth permissions, requiring admin approval for third-party apps, enabling Continuous Access Evaluation, and monitoring Entra logs for deviceCode activity, along with applying published IoCs.

Microsoft rejects critical Azure vulnerability report, no CVE issued
Security researcher Justin O'Leary alleges a critical privilege-escalation flaw in Azure Backup for AKS that could let a user with only the Backup Contributor role gain cluster-admin rights via the Trusted Access mechanism. Microsoft says the behavior was expected and that no product changes or CVE were issued, despite O'Leary's claims and evidence of new permission checks and failed exploits after disclosure. CERT/CC independently validated the issue, assigned a tracking ID, and initially scheduled public CVE disclosure, but Microsoft lobbied MITRE to block a CVE and CERT/CC closed the case under CNA rules. After the disclosure, the attacker path reportedly no longer works; Microsoft now requires manual Trusted Access configuration and added permission checks, suggesting the vulnerability was fixed without a public advisory. The episode underscores the 'validation gap' and the challenge defenders face when CVEs or public advisories are absent.

Russian hackers turn Kazuar backdoor into modular P2P botnet
Russian hacker group Secret Blizzard has upgraded the Kazuar backdoor into a modular, peer-to-peer botnet designed for long-term persistence, stealth, and data exfiltration. The malware now uses three modules—Kernel (leader election and task orchestration), Bridge (external C2 proxy), and Worker (keylogging, screenshots, data harvesting, and reconnaissance)—with around 150 configurable options, including AMSI, ETW, and WLDP bypasses. Communications are AES-encrypted and protobuf-serialized via IPC. Microsoft warns this evolution increases evasion, urging defenses to emphasize behavioral detection. The botnet targets government and critical infrastructure across Europe, Asia, and Ukraine.

Critical Funnel Builder WordPress Plugin Bug Exploited to Steal Credit Card Data on WooCommerce Checkouts
Security researchers revealed a critical unauthenticated vulnerability in Funnel Builder for WordPress that injects malicious JavaScript into WooCommerce checkout pages, enabling theft of credit card data. The flaw affects all versions prior to 3.15.0.3 and can be triggered through an exposed checkout endpoint to modify the plugin’s External Scripts setting, loading a skimmer that collects card numbers, CVVs, billing addresses, and other customer data. The malicious payload is disguised as a fake Google Tag Manager/Analytics script and communicates with an attacker-controlled server. FunnelKit released version 3.15.0.3 to fix the issue; admins should update immediately and audit External Scripts for rogue entries. The attack was detected by Sansec and reportedly affects more than 40,000 sites.

Avada Builder WordPress plugin flaws allow site credential theft
Two flaws in the Avada Builder WordPress plugin (CVE-2026-4782 and CVE-2026-4798) could let attackers read arbitrary files (potentially exposing wp-config.php) and perform a time-based SQL injection, affecting roughly one million installations. Exploitation paths include authenticated subscriber access for file reads and unauthenticated access when WooCommerce is present and later deactivated. Patches were released as 3.15.2 (partial) and 3.15.3 (fully patched) with 3.15.3 released on May 12, 2026; site owners should update immediately.

Microsoft to automatically roll back faulty Windows drivers
Microsoft is piloting Cloud-Initiated Driver Recovery to remotely roll back faulty Windows Update drivers to a previous stable version, eliminating the need for partners or users to intervene. The recovery, managed entirely by Microsoft through Windows Update for drivers rejected during shiproom evaluation, will be tested May–August 2026 and roll out starting September 2026 as part of the Driver Quality Initiative and broader resiliency efforts.

Microsoft warns of Exchange zero-day flaw exploited in attacks
Microsoft warns of a high-severity Exchange Server zero-day (CVE-2026-42897) exploited via cross-site scripting to run arbitrary code in Outlook on the Web. The flaw affects Exchange 2016, Exchange 2019, and Exchange SE, with no permanent patch available yet. For immediate protection, Microsoft recommends enabling Exchange Emergency Mitigation Service (EEMS); an on-premises mitigation via EEMS is automatic on eligible servers, and the Exchange On-Premises Mitigation Tool (EOMT) remains an option for air-gapped environments. Patches are planned for Exchange SE RTM, Exchange 2016 CU23, and Exchange 2019 CU14/CU15, though updates for 2016/2019 may be limited to customers in the Period 2 ESU program. CISA and NSA have previously issued guidance to harden Exchange servers against such exploits.

TeamPCP Hackers Advertise Mistral AI Code Repos for Sale
TeamPCP hackers are offering nearly 450 Mistral AI repositories for sale at $25,000, with a one-week deadline before they leak the data. They claim the stolen data covers training, fine-tuning, benchmarking, model delivery, and inference materials from Mistral AI, tied to the TanStack supply-chain attack that also compromised CI/CD credentials and multiple npm/PyPI packages. Mistral AI says the breach touched some SDK packages but did not affect core repositories or hosted services, while OpenAI confirms related impacts and has rotated certificates and pushed updates for affected users.
Showing 20 of 423 articles


