Последние посты

SITREP - Independent OSINT Channel
25 сент., 11:47
📡 Corp MDM spyware expands mobile control over logistics targetsA new Android threat tracked as Corp MDM is targeting logistics firms with spyware functions tied to device management abuse. Reported capabilities include intercepting newly received SMS messages and redirecting phone calls, extending access beyond standard surveillance into active control of communications.The combination is operationally significant for transport and supply-chain environments where SMS-based verification, dispatcher coordination, and voice calls remain core workflows. Call redirection and fresh SMS capture can enable account takeover, message interception, and disruption of routine business communications.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
25 сент., 10:43
📡 Roundcube flaw moves from patch advisory to active exploitationThe Canadian Centre for Cyber Security has flagged CVE-2026-48842 as exploited in the wild. The bug, patched in May in Roundcube 1.6.16 and 1.7.1, is a pre-auth SQL injection in the virtuser_query plugin that can enable auth bypass, malicious database commands, and data theft without user interaction.The exposure is structurally significant: Roundcube is widely deployed, including as a default interface in many hosting environments, and internet-facing inventory runs into the hundreds of thousands. Immediate mitigation is patching; where upgrades are delayed, disabling or removing virtuser_query cuts the stated attack path.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
25 сент., 09:51
📡 MacSync shifts payload delivery to public iCloud calendarsA new MacSync variant targeting macOS uses public iCloud calendar events to stage commands and fetch follow-on payloads from iCloud. Kaspersky says the Swift-based stealer, previously linked to AMOS lineage, is being distributed via ClickFix-style lures and fake apps, including a bogus crypto wallet. A new Objective-C backdoor module also impersonates Finder.The tradecraft blends legitimate Apple cloud services with multi-stage execution, reducing infrastructure visibility and complicating blocking. Persistence through LaunchAgent entries, .zshrc changes, and global Git hooks, plus theft of browser, wallet, Keychain, SSH, AWS, Kubernetes, and Telegram data, makes the campaign both evasive and broad in collection scope.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
25 сент., 08:56
🤖 MikroTrick chain exposed in MikroTik RouterOSCERT Polska reconstructed the MikroTrick attack chain days after MikroTik’s September 3 patch, identifying CVE-2026-67279 and CVE-2026-86060 as a path to full unauthenticated admin access. The chain abuses SSH rekey handling before authentication and a username parsing flaw using “-2,” with logs showing failed login attempts followed by creation of a privileged “ops” account.The case shows how patch diffing, forum log review, and AI-assisted protocol testing can collapse the window between vendor release and public reverse engineering. Defenders are still constrained by patch deployment and compromise assessment, while exploit reconstruction now moves in days.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
25 сент., 07:57
⚡ WSO2 and Adobe Commerce flaws added to KEVCISA has added actively exploited vulnerabilities affecting WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities catalog. The listing confirms observed exploitation and places both enterprise middleware and e-commerce platforms into the federal remediation queue.The move raises priority for defenders beyond routine patching. KEV inclusion is a practical signal that these bugs have crossed from theoretical exposure into operational use, increasing urgency for asset identification, exposure mapping, and accelerated remediation timelines.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
25 сент., 06:56
🔍 Salesforce Agentforce flaws enabled 0-click CRM exfiltrationThree vulnerabilities dubbed SalesBleed let poisoned Web-to-Lead submissions hijack Agentforce, query CRM records, and leak data via rendered image requests or Slack URL unfurling without user clicks. A third issue in Slack thread replies allowed phishing messages to be sent under the agent’s identity without user confirmation or visible attribution. Salesforce has fixed all three issues.The case shows how public input channels, agent tool access, and output rendering can combine into a silent exfiltration path. It also highlights that trusted in-platform agent identities can be repurposed for phishing if action controls and attribution are weak.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
25 сент., 06:05
🔍 Placeholder domain in 1,700+ repos now delivering malicious contentA domain used as a sample third-party reference across more than 1,700 public code repositories has been repurposed to serve malicious material, creating a supply-chain style exposure for projects that left the placeholder active in production paths. The placeholder domain was broadly embedded in code, documentation, and configurations.The issue is not a software bug but a trust failure around dormant external dependencies. Any hardcoded external reference, even a “temporary” one, can become an attack surface if ownership changes or content is swapped after deployment.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
25 сент., 05:00
🤖 Carbonato targets exposed Docker daemonsCarbonato is a botnet malware targeting Docker APIs exposed on port 2375 without authentication. It deploys a privileged container, opens reverse SSH access, installs the Hermes Agent framework with a GH0ST persona, reports via Telegram, and persists through cron, systemd, rc.local, and OpenRC. Researchers traced operational artifacts from October 2024 to August 2026.The key shift is the pairing of container compromise with an operator-driven AI agent loop. Beyond initial access, the malware can execute commands, collect keys and credentials, and scan attached networks every five minutes to spread to other exposed Docker hosts.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 13:24
📄 FBI CJIS v6.1 tightens encryption and scanning cadenceThe FBI’s CJIS Security Policy v6.1, published 25 June 2026, keeps the v6.0 control-based structure but raises key technical baselines. Encryption for CJI in transit under SC-13 now requires at least 256-bit symmetric strength, up from 128-bit, while SC-28 sets 256-bit protection for CJI at rest. Vulnerability scanning frequency also shifts from quarterly to at least monthly.The update does not reset audit practice overnight. Priority 1 controls remain sanctionable, while Priority 2-4 stay in zero-cycle status until 30 September 2027, and some state CSAs are still auditing older baselines. For defenders, the shift is less about new direction than faster verification, stronger crypto, and continuous evidence of control effectiveness.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 12:32
📡 III Armored Corps starts baseline NGC2 fieldingIII Armored Corps has begun receiving the transport and infrastructure layers of the Army’s Next Generation Command and Control stack, making it the first unit to divest legacy WIN-T gear under the new consolidated fielding process. The package includes SATCOM antennas, automated traffic management tools, and forward servers with cloud access for DDIL operations.This marks a shift from extended experimentation to operational rollout. The Army is establishing a common baseline network architecture before adding NGC2’s data and application layers, while reducing deployment time and legacy system burden across the force.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 11:35
📡 Pentagon awards GEO surveillance satellite prototypes under GHOST-RSpace Systems Command and the Defense Innovation Unit awarded prototype contracts to Northrop Grumman and True Anomaly for GHOST-R, a Space Force effort to field satellites that can image and characterize other objects in geostationary orbit. Launch is planned for 2028, with transition to government-led operations in 2029. Contract values were not disclosed.The program points to a push for distributed, commercially derived space-domain awareness in GEO, with emphasis on tracking, approaching, and identifying resident space objects as orbital congestion and counterspace risks grow.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 10:43
🔍 RansomHouse named in breach of Namibia defense ministry networkNamibia’s national cyber team has confirmed unauthorized activity inside the Ministry of Defence and Veterans Affairs network and directly linked the incident to RansomHouse. The group listed the “Namibian Defence Force” on its leak site on 16 September. Authorities have not disclosed whether data was stolen, systems were encrypted, or a ransom was demanded.The notable point is the public attribution by NAM-CSIRT at an early stage. What remains unclear is the actual impact on defense systems, data exposure, and recovery timeline, leaving the current operational effect unconfirmed.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 09:42
📡 BigCommerce isolates app-linked customer data breachBigCommerce notified multiple merchants after attackers used compromised credentials for third-party apps Ribon and Ribon 1.5 to inject malicious scripts and access shopper records between September 13 and 17. The company removed the apps on September 17 and says platform systems, passwords, and payment card data were not exposed. UK retailer Master of Malt said names, emails, phone numbers, and shipping addresses were accessed.The incident highlights a familiar SaaS supply-chain weakness: trusted app keys can provide direct access into merchant environments without a breach of the core platform. BigCommerce’s response contained access by uninstalling the apps, but the case shows how third-party integrations remain a high-value path to customer data.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 08:49
🔍 TASK#STOMP PowerShell backdoor targets local data collectionThe TASK#STOMP backdoor is described as a PowerShell-based malware focused on stealing documents, Wi-Fi passwords, and clipboard contents from compromised Windows systems. The reported collection set indicates direct harvesting of user files, stored network credentials, and transient data copied through the clipboard.The combination is operationally notable because it supports both immediate data theft and follow-on access. Wi-Fi credentials can extend intrusion paths, clipboard capture can expose passwords or crypto wallets, and document theft suggests prioritization of locally accessible intelligence over destructive effects.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 07:49
🔍 CISA flags three actively exploited Linux kernel flawsCISA added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch or mitigate by end of day. The issues affect AF_ALG, ebtables SNAT, and the kTLS receive path; one bug reportedly existed in the kernel for 14 years.The operational signal is the “forensic triage” requirement: CISA is treating exposure as a potential compromise, not just a patching gap. Public exploit availability has been confirmed for two of the three flaws, raising urgency for Linux fleets, containers, and systems using kTLS.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 06:53
🔍 Contagious Interview campaign hit 30,000 devices, drained $10.71MThe Contagious Interview campaign reportedly compromised 30,000 devices and stole $10.71 million in cryptocurrency. The operation used a fake job interview lure to deliver malware, combining social engineering with direct financial theft at scale.The case underlines how recruitment-themed intrusion chains remain effective for initial access, especially against users willing to run files or join staged interview workflows. The volume of infected endpoints and the monetization outcome indicate a mature theft pipeline rather than isolated opportunistic activity.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 06:02
🔍 Fake LastPass installer used to disable endpoint defensesA trojanized LastPass Authenticator installer was observed abusing a Microsoft-signed driver to terminate antivirus and EDR processes on Windows endpoints. The lure impersonates LastPass software while the signed kernel component gives the malware a trusted path to interfere with defensive tooling, as outlined in the installer analysis.The tradecraft combines brand impersonation with driver abuse to neutralize host visibility before follow-on activity. For defenders, the key indicators are unexpected LastPass-themed installers, unsigned userland components paired with trusted drivers, and abrupt security product termination events.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
22 сент., 05:00
🔍 NightEagle expands GhostContainer operations onto Russian Exchange infrastructureKaspersky says NightEagle, also tracked as APT-Q-95, targeted Microsoft Exchange servers at Russian organizations with the GhostContainer backdoor. Initial access was linked to compromised VPN credentials, after which the group reportedly abused Exchange VIEWSTATE handling to launch the implant in memory, then used RDP, dev tunnels, Impacket atexec, and DCSync techniques for movement and persistence.The activity is notable for combining valid-account access, fileless Exchange execution, and built-in or legitimate remote-access channels to reduce forensic visibility. On-prem Exchange and exposed RDP paths remain the key pressure points, especially where older flaws and weak credential hygiene overlap.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
21 сент., 12:42
⚡ Windows update backlog turns a dormant laptop into a 7-hour recovery cycleA Windows 11 laptop left inactive for a few months reportedly required roughly seven hours to return to a fully updated state. The process involved cumulative OS updates, a newer Windows release, firmware and driver packages, and repeated restarts on standard production hardware.The case undercuts vendor messaging around efficiency gains. Faster startup and lower memory use have limited operational value if infrequently used systems face hours-long patch recovery before they become usable. For users and admins, update volume and dependency chains remain a practical availability issue.🛰️ Open sources - closed narratives @sitreports


SITREP - Independent OSINT Channel
21 сент., 11:39
🔍 SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115Security Affairs has published Malware Newsletter Round 115, a curated digest of recent malware research. The roundup spans one-click backdoors, Linux rootkits, browser-extension abuse, Chrome and Windows exploit chains, MQTT-based infection management, Central Asia-focused infrastructure, WordPress supply-chain compromise, mobile credential theft, and multiple academic papers on malware detection.The list captures the current spread of activity across user endpoints, web supply chains, mobile devices, and AI-assisted analysis. Operationally, it shows simultaneous pressure on patch management, extension trust models, developer platforms, and detection pipelines rather than a single dominant intrusion path.🛰️ Open sources - closed narratives @sitreports

