<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FHN &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/author/fhn/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Mon, 10 Aug 2026 22:07:31 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.6</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>FHN &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Android Banking Malware Adopts New Evasion Techniques</title>
		<link>https://firsthackersnews.com/android-banking-malware-evasion-techniques/</link>
					<comments>https://firsthackersnews.com/android-banking-malware-evasion-techniques/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 13:46:00 +0000</pubDate>
				<category><![CDATA[Android banking trojan]]></category>
		<category><![CDATA[Android malware]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Android Banking Malware]]></category>
		<category><![CDATA[android malware]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Malware Droppers]]></category>
		<category><![CDATA[Mobile Banking Security]]></category>
		<category><![CDATA[mobile malware]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12169</guid>

					<description><![CDATA[<p>Android banking malware continues to evolve as cybercriminals adopt new methods to avoid detection and bypass app store</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-banking-malware-evasion-techniques/">Android Banking Malware Adopts New Evasion Techniques</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Android banking malware continues to evolve as cybercriminals adopt new methods to avoid detection and bypass app store security checks. Instead of distributing banking malware directly, attackers are increasingly using <strong>dropper applications</strong> that deliver the malicious payload only after the app has been installed.</p>



<p>According to recent security research, while the overall number of blocked Android malware attacks declined during the second quarter of 2026, banking malware remains one of the most active mobile threats. Rather than disappearing, attackers are changing how their malware is packaged and deployed.</p>



<h2 class="wp-block-heading"><strong>A Shift Toward Dropper-Based Attacks</strong></h2>



<p>A dropper is an application that appears harmless but is designed to download or activate malware after installation.</p>



<p>This approach allows attackers to hide the real banking Trojan during the initial app review process. Once the application is installed on a victim&#8217;s device, it can retrieve additional malicious components and begin targeting banking credentials.</p>



<p>By separating the delivery mechanism from the actual malware, cybercriminals can update or replace their payloads without creating entirely new malicious applications.</p>



<h2 class="wp-block-heading"><strong>Malicious Apps Disguised as Legitimate Software</strong></h2>



<p>Researchers observed attackers disguising malware as legitimate Android applications, including utility and document reader apps.</p>



<p>In one campaign, a PDF reader displayed what appeared to be a routine software update notification. Instead of installing an update, the application downloaded banking malware onto the victim&#8217;s device.</p>



<p>These fake update prompts make malicious activity appear normal, increasing the likelihood that users will unknowingly install the malware.</p>



<h2 class="wp-block-heading"><strong>Smarter Delivery Techniques</strong></h2>



<p>Modern Android droppers are becoming more selective in how they deliver malware.</p>



<p>Some applications first collect information about where they were downloaded and send that data to a command-and-control (C2) server. The server decides whether to deliver the malicious payload based on the installation source.</p>



<p>This selective delivery helps attackers avoid security researchers, automated analysis tools, and app store review systems while targeting real users.</p>



<h2 class="wp-block-heading"><strong>Banking Malware Continues to Evolve</strong></h2>



<p>Security researchers also observed continued activity from well-known Android banking malware families, including <strong>Mamont</strong> and <strong>Creduz</strong>.</p>



<p>New variants are being released regularly, suggesting that malware operators are continuously testing new delivery techniques, improving evasion methods, and developing updated versions to avoid detection.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>The growing use of droppers shows that mobile threats are becoming more sophisticated. A reduction in traditional banking Trojan detections does not necessarily indicate a lower risk—it may simply reflect changes in how malware is delivered.</p>



<p>As attackers continue refining their techniques, users and organizations should remain cautious of applications that request unexpected updates or unnecessary permissions.</p>



<h2 class="wp-block-heading"><strong>How to Stay Protected</strong></h2>



<p>To reduce the risk of Android banking malware:</p>



<ul class="wp-block-list">
<li>Install apps only from trusted sources.</li>



<li>Keep Google Play Protect enabled.</li>



<li>Avoid downloading apps from unofficial websites.</li>



<li>Be cautious of unexpected in-app update requests.</li>



<li>Review requested permissions before installing applications.</li>



<li>Keep Android devices and applications updated.</li>



<li>Use a reputable mobile security solution.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Android banking malware operators are shifting away from traditional delivery methods and increasingly relying on dropper applications to bypass security controls. As these techniques become more advanced, mobile users and organizations should strengthen their security practices, verify application sources, and remain alert to suspicious app behavior to reduce the risk of financial compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-banking-malware-evasion-techniques/">Android Banking Malware Adopts New Evasion Techniques</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/android-banking-malware-evasion-techniques/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CISA Warns of Active LoadMaster Attacks</title>
		<link>https://firsthackersnews.com/progress-loadmaster-vulnerability/</link>
					<comments>https://firsthackersnews.com/progress-loadmaster-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 03:07:00 +0000</pubDate>
				<category><![CDATA[CISA]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[cisa kev]]></category>
		<category><![CDATA[command injection]]></category>
		<category><![CDATA[CVE-2026-8037]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[LoadMaster Security]]></category>
		<category><![CDATA[LoadMaster Vulnerability]]></category>
		<category><![CDATA[Progress LoadMaster]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12173</guid>

					<description><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert after confirming that a critical vulnerability</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/progress-loadmaster-vulnerability/">CISA Warns of Active LoadMaster Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert after confirming that a critical vulnerability in <strong>Progress LoadMaster</strong> is being actively exploited. The flaw, tracked as <strong>CVE-2026-8037</strong>, has now been added to CISA&#8217;s <strong>Known Exploited Vulnerabilities (KEV)</strong> catalog, highlighting the urgent need for organizations to patch affected systems.</p>



<p>The vulnerability allows remote attackers to execute commands on vulnerable devices without requiring authentication. Since LoadMaster appliances are commonly deployed at the network edge to manage application traffic, a successful attack could provide threat actors with an entry point into an organization&#8217;s infrastructure.</p>



<h2 class="wp-block-heading"><strong>What Is the Vulnerability?</strong></h2>



<p>CVE-2026-8037 is a <strong>command injection vulnerability</strong> affecting the API component of Progress LoadMaster and related Application Delivery Controller (ADC) products.</p>



<p>The flaw occurs because certain user-supplied input is not properly validated before being processed by the operating system. As a result, attackers can craft malicious requests that force the appliance to execute unauthorized system commands.</p>



<p>Most importantly, the attack does <strong>not require valid login credentials</strong>, making internet-facing devices particularly vulnerable.</p>



<h2 class="wp-block-heading"><strong>Why the Risk Is So High</strong></h2>



<p>Security researchers have assigned the vulnerability a <strong>CVSS score of 9.6</strong>, reflecting its critical severity.</p>



<p>Because LoadMaster appliances often sit at the perimeter of enterprise networks, compromising one could allow attackers to:</p>



<ul class="wp-block-list">
<li>Execute remote commands.</li>



<li>Gain an initial foothold inside the network.</li>



<li>Steal credentials.</li>



<li>Move laterally to other systems.</li>



<li>Deploy additional malware or backdoors.</li>



<li>Modify device configurations.</li>
</ul>



<p>Public proof-of-concept (PoC) exploit code is also available, making it easier for attackers to scan for and target vulnerable systems.</p>



<h2 class="wp-block-heading"><strong>Active Exploitation Confirmed</strong></h2>



<p>According to CISA, the vulnerability is no longer a theoretical threat.</p>



<p>Evidence of active exploitation prompted the agency to add CVE-2026-8037 to its KEV catalog and advise affected organizations to apply vendor updates immediately.</p>



<p>Although there are currently no reports linking the flaw to ransomware campaigns, attackers are actively attempting to exploit vulnerable devices exposed to the internet.</p>



<h2 class="wp-block-heading"><strong>Recommended Security Measures</strong></h2>



<p>Organizations using Progress LoadMaster should act immediately by:</p>



<ul class="wp-block-list">
<li>Identifying all affected LoadMaster appliances.</li>



<li>Applying the latest security updates provided by Progress.</li>



<li>Restricting management and API access to trusted networks or VPNs.</li>



<li>Reviewing logs for unusual API requests and command execution attempts.</li>



<li>Investigating unexpected configuration changes or unauthorized administrative activity.</li>



<li>Conducting a full security assessment after patching to ensure attackers have not already established persistence.</li>
</ul>



<p>The inclusion of <strong>CVE-2026-8037</strong> in CISA&#8217;s Known Exploited Vulnerabilities catalog underscores the seriousness of this security issue. Since the vulnerability can be exploited without authentication and public exploit code is already available, organizations should prioritize patching affected LoadMaster systems and closely monitor their environments for signs of compromise.</p>



<p>Taking prompt action can significantly reduce the risk of attackers gaining access to critical network infrastructure.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/progress-loadmaster-vulnerability/">CISA Warns of Active LoadMaster Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/progress-loadmaster-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical WordPress Flaw Enables Remote Code Execution</title>
		<link>https://firsthackersnews.com/wordpress-xss2shell-flaw/</link>
					<comments>https://firsthackersnews.com/wordpress-xss2shell-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 07 Aug 2026 22:13:30 +0000</pubDate>
				<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Web application security]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[CVE-2026-64638]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[WordPress Security]]></category>
		<category><![CDATA[wordpress vulnerability]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[XSS2Shell]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12164</guid>

					<description><![CDATA[<p>Security researchers have uncovered a serious vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and known as XSS2Shell.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/wordpress-xss2shell-flaw/">Critical WordPress Flaw Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have uncovered a serious vulnerability chain in <strong>WordPress Core</strong>, tracked as <strong>CVE-2026-64638</strong> and known as <strong>XSS2Shell</strong>. The flaw could allow attackers to escalate from a simple login page attack to <strong>remote code execution (RCE)</strong> under specific conditions.</p>



<p>Because the vulnerable code has been part of WordPress since <strong>version 4.7</strong>, millions of websites using one of the world&#8217;s most popular content management systems were potentially exposed before security updates were released.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>The attack begins on WordPress&#8217;s standard login page (<strong>wp-login.php</strong>).</p>



<p>When someone attempts to log in with an invalid username, WordPress displays an error message. Researchers discovered that specially crafted input can bypass the platform&#8217;s HTML filtering due to differences in how PHP and WordPress process certain characters.</p>



<p>This allows malicious HTML elements to appear within the login page even though no authentication is required.</p>



<p>Although these injected elements do not contain JavaScript themselves, they can interact with existing WordPress scripts already loaded in the browser.</p>



<h2 class="wp-block-heading"><strong>From XSS to Code Execution</strong></h2>



<p>The injected content takes advantage of WordPress&#8217;s built-in JavaScript files, which automatically process specific page elements.</p>



<p>By manipulating these interactions, attackers can trigger unauthorized browser requests and eventually execute JavaScript within the WordPress website.</p>



<p>On its own, this reflected Cross-Site Scripting (XSS) vulnerability is already a serious security concern. However, researchers demonstrated that the attack can become far more dangerous when combined with social engineering.</p>



<p>If a logged-in administrator visits a specially crafted website and interacts with it, an attacker may abuse the administrator&#8217;s active session to perform privileged WordPress actions without their knowledge.</p>



<h2 class="wp-block-heading"><strong>Potential Impact</strong></h2>



<p>Successful exploitation could allow attackers to:</p>



<ul class="wp-block-list">
<li>Execute malicious JavaScript.</li>



<li>Create new WordPress application passwords.</li>



<li>Publish unauthorized content.</li>



<li>Upload malicious plugins.</li>



<li>Deploy PHP web shells.</li>



<li>Achieve remote code execution on the server.</li>
</ul>



<p>Since these actions are performed using legitimate administrator privileges, detecting the attack can be more challenging.</p>



<h2 class="wp-block-heading"><strong>Who Is Affected?</strong></h2>



<p>The vulnerability affects WordPress Core versions dating back to <strong>4.7</strong>, making it one of the broadest WordPress security issues disclosed in recent years.</p>



<p>Given WordPress powers a significant portion of websites worldwide, organizations running outdated installations should review their environments immediately.</p>



<h2 class="wp-block-heading"><strong>Security Update Available</strong></h2>



<p>The WordPress security team addressed the issue in <strong>WordPress 7.0.3</strong> and also released security updates for older supported branches.</p>



<p>The vulnerability was assigned a <strong>CVSS score of 8.9 (High)</strong> due to its potential impact. While the full attack chain requires administrator interaction, the possibility of remote code execution makes prompt patching essential.</p>



<p>At the time of disclosure, researchers reported <strong>no confirmed evidence of active exploitation</strong> in real-world attacks.</p>



<h2 class="wp-block-heading"><strong>How to Protect Your WordPress Site</strong></h2>



<p>Website owners and administrators should take the following steps:</p>



<ul class="wp-block-list">
<li>Update WordPress to the latest supported version.</li>



<li>Apply all available security patches.</li>



<li>Restrict administrator access to trusted users.</li>



<li>Review installed plugins and themes regularly.</li>



<li>Enable multi-factor authentication (MFA) for administrator accounts.</li>



<li>Monitor login activity and unexpected administrative actions.</li>



<li>Use a Web Application Firewall (WAF) to help block suspicious requests.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>The <strong>XSS2Shell</strong> vulnerability demonstrates how a seemingly minor login page weakness can evolve into a much more serious attack when combined with browser behavior and administrator interaction.</p>



<p>Although exploitation requires specific conditions, the potential for remote code execution makes this vulnerability a high priority for WordPress administrators. Keeping WordPress updated and following security best practices remain the most effective ways to reduce the risk of compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/wordpress-xss2shell-flaw/">Critical WordPress Flaw Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/wordpress-xss2shell-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Windows Hello Key Flaw Opens Door to Entra ID Access</title>
		<link>https://firsthackersnews.com/windows-hello-for-business-security-flaw/</link>
					<comments>https://firsthackersnews.com/windows-hello-for-business-security-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 07 Aug 2026 15:50:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Windows Security]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Entra ID]]></category>
		<category><![CDATA[identity security]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[Microsoft Entra]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[Passwordless Authentication]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Windows Hello for Business]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[Zero Trust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12149</guid>

					<description><![CDATA[<p>Security researcher Dirk-jan Mollema has uncovered a new technique that could allow attackers to misuse Windows Hello for</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/windows-hello-for-business-security-flaw/">Windows Hello Key Flaw Opens Door to Entra ID Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researcher <strong>Dirk-jan Mollema</strong> has uncovered a new technique that could allow attackers to misuse <strong>Windows Hello for Business (WHFB)</strong> to authenticate to Microsoft Entra ID services without requiring the victim&#8217;s password, PIN, or biometric verification.</p>



<p>Rather than breaking Windows Hello encryption, the technique takes advantage of an already authenticated Windows session. If an attacker gains access to a logged-in device, they may be able to leverage the victim&#8217;s existing Windows Hello credentials to request authentication tokens and potentially establish long-term access to Microsoft Entra resources.</p>



<p>The research highlights how attackers can abuse trusted authentication mechanisms once an endpoint has already been compromised.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>Windows Hello for Business replaces passwords with cryptographic keys that are securely stored on the user&#8217;s device, typically inside the <strong>Trusted Platform Module (TPM)</strong>. These keys are designed to remain protected and cannot normally be exported from the device.</p>



<p>However, the research demonstrates that an application running with standard user privileges inside an active Windows session can request cryptographic operations from the Windows Hello key without asking the user to re-enter their PIN or biometric authentication.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="282" src="https://firsthackersnews.com/wp-content/uploads/2026/08/image-1024x282.png" alt="" class="wp-image-12153" srcset="https://firsthackersnews.com/wp-content/uploads/2026/08/image-300x83.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-768x212.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-1024x282.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/08/image-1536x423.png 1536w, https://firsthackersnews.com/wp-content/uploads/2026/08/image.png 1600w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><strong>Windows Hello Authentication Flow (Source: Dirk-jan Mollema)</strong></figcaption></figure>



<p>Instead of stealing the private key itself, the attacker simply instructs Windows to use it on their behalf. As long as the user remains logged in, Windows considers the authentication request valid.</p>



<p>This effectively allows attackers to &#8220;borrow&#8221; the trusted Windows Hello credentials without directly compromising them.</p>



<h2 class="wp-block-heading"><strong>Authentication Without Traditional Credentials</strong></h2>



<p>Researchers showed that the borrowed Windows Hello key can be used during Microsoft&#8217;s <strong>WebAuthn</strong> authentication process.</p>



<p>Since the authentication challenge is not permanently tied to a specific device or session, attackers can generate the request from their own system while having the victim&#8217;s compromised device perform the required cryptographic signing.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<p>Once the challenge is successfully signed, Microsoft Entra treats the authentication as legitimate and issues cloud authentication tokens.</p>



<p>Unlike earlier attack techniques, this approach removes the need for attackers to control another Microsoft Entra-registered device, making exploitation significantly easier.</p>



<h2 class="wp-block-heading"><strong>Potential Impact</strong></h2>



<p>Successful exploitation could provide attackers with access to Microsoft Entra cloud resources while using legitimate authentication mechanisms.</p>



<p>Depending on the organization&#8217;s security configuration, attackers may be able to:</p>



<ul class="wp-block-list">
<li>Authenticate to Microsoft Entra services.</li>



<li>Obtain cloud authentication tokens.</li>



<li>Register attacker-controlled devices.</li>



<li>Add new authentication methods.</li>



<li>Maintain persistent access to cloud identities.</li>



<li>Expand access across enterprise environments.</li>
</ul>



<p>Because Windows Hello for Business satisfies multi-factor authentication requirements, attackers may also bypass additional protections designed to secure identity management functions.</p>



<h2 class="wp-block-heading"><strong>Why Organizations Should Pay Attention</strong></h2>



<p>The research demonstrates that passwordless authentication is only as secure as the endpoint itself.</p>



<p>Even though Windows Hello protects credentials from theft, an attacker who compromises an active Windows session may still abuse trusted authentication processes without ever knowing the user&#8217;s password or PIN.</p>



<p>This reinforces the importance of endpoint security alongside identity protection.</p>



<p>Organizations should not rely solely on passwordless authentication but should also focus on preventing attackers from gaining access to active user sessions.</p>



<h2 class="wp-block-heading"><strong>Detection and Mitigation</strong></h2>



<p>Security teams should monitor Microsoft Entra sign-in activity for unusual Windows Hello authentication events, particularly those that do not contain an associated device ID.</p>



<p>Administrators should also investigate unexpected device registrations, monitor changes to authentication methods, strengthen endpoint detection and response capabilities, and regularly review Conditional Access policies to ensure only trusted devices can register new authentication factors.</p>



<p>Monitoring active user sessions and detecting suspicious endpoint activity remain critical for preventing attackers from abusing trusted authentication mechanisms.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Mollema&#8217;s research demonstrates that compromising an active Windows session can have serious consequences, even in environments that have adopted passwordless authentication.</p>



<p>While the technique does not break Windows Hello&#8217;s cryptographic protections, it shows how trusted authentication workflows can be abused after an endpoint has been compromised.</p>



<p>Organizations using Windows Hello for Business and Microsoft Entra should prioritize endpoint protection, continuous monitoring, and identity security controls to reduce the risk of attackers turning temporary access into persistent cloud compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/windows-hello-for-business-security-flaw/">Windows Hello Key Flaw Opens Door to Entra ID Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/windows-hello-for-business-security-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Linux Kernel Flaw Grants Root Access</title>
		<link>https://firsthackersnews.com/critical-linux-kernel-flaw-root-access/</link>
					<comments>https://firsthackersnews.com/critical-linux-kernel-flaw-root-access/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 07 Aug 2026 13:33:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Linux Malware]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Container Escape]]></category>
		<category><![CDATA[Container Security]]></category>
		<category><![CDATA[CVE-2026-64564]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[kernel vulnerability]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux kernel]]></category>
		<category><![CDATA[Linux security]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[root access]]></category>
		<category><![CDATA[SCTPhantom]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12145</guid>

					<description><![CDATA[<p>A newly discovered Linux kernel vulnerability, tracked as CVE-2026-64564 and named SCTPhantom, could allow attackers with local access</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/critical-linux-kernel-flaw-root-access/">Critical Linux Kernel Flaw Grants Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly discovered Linux kernel vulnerability, tracked as <strong>CVE-2026-64564</strong> and named <strong>SCTPhantom</strong>, could allow attackers with local access to gain full root privileges. Security researchers also demonstrated that the flaw can be used to escape containers and compromise the underlying host system, making it a serious risk for Linux environments.</p>



<p>The vulnerability affects the <strong>Stream Control Transmission Protocol (SCTP)</strong> component of the Linux kernel. Surprisingly, the underlying flaw has existed since <strong>Linux 2.6.25</strong>, released in <strong>2007</strong>, meaning it remained undiscovered for nearly 18 years.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>The issue is caused by a <strong>use-after-free</strong> memory bug in SCTP&#8217;s <strong>Dynamic Address Reconfiguration (ASCONF)</strong> feature.</p>



<p>By sending specially crafted SCTP packets in a specific sequence, an attacker can trick the kernel into freeing an object while it is still being referenced. When the kernel later tries to access that memory, it creates a use-after-free condition that can be exploited.</p>



<p>This flaw allows attackers to manipulate kernel memory and eventually execute privileged operations.</p>



<h2 class="wp-block-heading"><strong>Privilege Escalation to Root</strong></h2>



<p>Researchers from TencentOS Security Team developed a working exploit that successfully turns the vulnerability into a full privilege-escalation attack.</p>



<p>Their exploit leaks kernel memory addresses, bypasses security protections such as <strong>Kernel Address Space Layout Randomization (KASLR)</strong>, and creates fake kernel objects to obtain root privileges.</p>



<p>Notably, the attack does not rely on shellcode or traditional Return-Oriented Programming (ROP) techniques, making it more difficult for some security solutions to detect.</p>



<h2 class="wp-block-heading"><strong>Container Escape Demonstrated</strong></h2>



<p>Researchers also proved that the vulnerability can be used to escape Linux containers.</p>



<p>Instead of requiring elevated system privileges, the exploit uses standard SCTP socket options available within containers. Once exploited, attackers can break out of the container environment and execute code on the underlying host.</p>



<p>This makes the vulnerability particularly concerning for organizations running containerized workloads or multi-tenant environments.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<h2 class="wp-block-heading"><strong>Affected Systems</strong></h2>



<p>The exploit was successfully tested on several Linux distributions, including:</p>



<ul class="wp-block-list">
<li>Ubuntu 24.04</li>



<li>Debian 13</li>



<li>Rocky Linux 9</li>



<li>Multiple Linux kernel versions from 5.14 through recent 7.x release candidates</li>
</ul>



<p>The researchers achieved root access on every tested environment.</p>



<h2 class="wp-block-heading"><strong>Severity and Impact</strong></h2>



<p>CVE-2026-64564 has received a <strong>CVSS v4.0 score of 8.5 (High)</strong>.</p>



<p>If exploited successfully, attackers could:</p>



<ul class="wp-block-list">
<li>Gain full root privileges</li>



<li>Escape container environments</li>



<li>Compromise the underlying host</li>



<li>Access sensitive data</li>



<li>Modify system configurations</li>



<li>Completely take control of affected Linux systems</li>
</ul>



<h2 class="wp-block-heading"><strong>Security Updates Available</strong></h2>



<p>The Linux kernel maintainers have released patches to address the vulnerability.</p>



<p>Fixes are available in the following kernel versions:</p>



<ul class="wp-block-list">
<li>6.6.148</li>



<li>6.12.101</li>



<li>6.18.42</li>



<li>7.1.6</li>
</ul>



<p>The vulnerability was officially disclosed on <strong>August 4, 2026</strong>, following responsible disclosure to the Linux kernel security team.</p>



<h2 class="wp-block-heading"><strong>How Organizations Can Protect Their Systems</strong></h2>



<p>Organizations running Linux servers should prioritize applying the latest kernel updates, especially if SCTP is enabled.</p>



<p>Security teams should also:</p>



<ul class="wp-block-list">
<li>Apply the latest patched kernel versions.</li>



<li>Monitor systems for unusual privilege-escalation attempts.</li>



<li>Limit local user access wherever possible.</li>



<li>Regularly review container security configurations.</li>



<li>Monitor kernel and authentication logs for suspicious activity.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>The discovery of <strong>SCTPhantom (CVE-2026-64564)</strong> highlights how critical vulnerabilities can remain hidden in widely used software for many years. With the ability to gain root access and escape containers, this flaw presents a significant security risk for Linux environments.</p>



<p>Organizations should update affected systems as soon as possible and strengthen monitoring to reduce the risk of exploitation.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/critical-linux-kernel-flaw-root-access/">Critical Linux Kernel Flaw Grants Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/critical-linux-kernel-flaw-root-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Top 10 Phishing Email Red Flags You Should Never Ignore</title>
		<link>https://firsthackersnews.com/top-10-phishing-email-red-flags/</link>
					<comments>https://firsthackersnews.com/top-10-phishing-email-red-flags/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 20:58:37 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Cyber Awareness]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Online Safety]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing emails]]></category>
		<category><![CDATA[Scam Prevention]]></category>
		<category><![CDATA[social engineering]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12141</guid>

					<description><![CDATA[<p>Phishing remains one of the most successful cyberattack techniques because it exploits human trust rather than technical vulnerabilities.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/top-10-phishing-email-red-flags/">Top 10 Phishing Email Red Flags You Should Never Ignore</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Phishing remains one of the most successful cyberattack techniques because it exploits human trust rather than technical vulnerabilities. Every day, attackers send fraudulent emails designed to steal credentials, distribute malware, or trick recipients into revealing sensitive information.</p>



<p>Understanding the warning signs of a phishing email is one of the most effective ways to reduce cyber risk. Below are ten common indicators that every individual and organization should recognize.</p>



<h2 class="wp-block-heading"><strong>1. Suspicious Sender Address</strong></h2>



<p>The sender&#8217;s email address is one of the first things to verify. Cybercriminals often register domains that closely resemble legitimate organizations by changing a single character or using uncommon domain extensions.</p>



<p>Always verify the sender before opening attachments or clicking links.</p>



<h2 class="wp-block-heading"><strong>2. Urgent or Fear-Inducing Messages</strong></h2>



<p>Phishing emails frequently create a false sense of urgency to pressure recipients into acting quickly.</p>



<p>Examples include:</p>



<ul class="wp-block-list">
<li>Your account has been suspended.</li>



<li>Immediate action required.</li>



<li>Your payment has failed.</li>



<li>Verify your identity now.</li>
</ul>



<p>Legitimate organizations rarely demand immediate action without providing alternative ways to verify the request.</p>



<h2 class="wp-block-heading"><strong>3. Suspicious Links</strong></h2>



<p>Before clicking any hyperlink, hover your cursor over it to view its actual destination.</p>



<p>If the displayed URL differs from the official company website or contains unusual characters, it should be treated as suspicious.</p>



<p>When in doubt, access the website directly through your browser instead of using the email link.</p>



<h2 class="wp-block-heading"><strong>4. Requests for Sensitive Information</strong></h2>



<p>Legitimate businesses do not typically request passwords, banking information, one-time passcodes, or confidential personal data through email.</p>



<p>Any message asking for sensitive information should be independently verified before responding.</p>



<h2 class="wp-block-heading"><strong>5. Poor Grammar and Unprofessional Formatting</strong></h2>



<p>Many phishing emails contain spelling mistakes, grammatical errors, inconsistent fonts, or unusual formatting.</p>



<p>Although modern phishing campaigns have become more convincing, poor language quality remains a common warning sign.</p>



<h2 class="wp-block-heading"><strong>6. Unexpected Attachments</strong></h2>



<p>Opening unexpected attachments can result in malware infections, ransomware attacks, or credential theft.</p>



<p>Be especially cautious with file types such as:</p>



<ul class="wp-block-list">
<li>ZIP</li>



<li>EXE</li>



<li>ISO</li>



<li>JS</li>



<li>DOCM</li>



<li>HTML</li>
</ul>



<p>If you were not expecting the attachment, confirm its legitimacy with the sender before opening it.</p>



<h2 class="wp-block-heading"><strong>7. Generic Greetings</strong></h2>



<p>Instead of addressing recipients by name, phishing emails often use generic greetings such as:</p>



<ul class="wp-block-list">
<li>Dear Customer</li>



<li>Dear User</li>



<li>Valued Customer</li>



<li>Dear Member</li>
</ul>



<p>Many legitimate organizations personalize important communications using your registered name.</p>



<h2 class="wp-block-heading"><strong>8. Offers That Seem Too Good to Be True</strong></h2>



<p>Cybercriminals frequently lure victims with attractive offers such as:</p>



<ul class="wp-block-list">
<li>Free gift cards</li>



<li>Lottery winnings</li>



<li>Large discounts</li>



<li>Tax refunds</li>



<li>Prize claims</li>
</ul>



<p>If an offer appears unusually generous or unexpected, verify it through the organization&#8217;s official website.</p>



<h2 class="wp-block-heading"><strong>9. Fake Branding and Logos</strong></h2>



<p>Attackers often copy company logos, email templates, and branding to make phishing emails appear authentic.</p>



<p>A professional-looking email does not guarantee legitimacy. Always verify the sender&#8217;s address and carefully inspect links before interacting with the message.</p>



<h2 class="wp-block-heading"><strong>10. Unexpected Login or Verification Requests</strong></h2>



<p>Many phishing campaigns direct victims to fake login pages designed to steal usernames and passwords.</p>



<p>If you receive an unexpected request to sign in or verify your account, avoid using the link provided in the email. Instead, manually enter the official website address into your browser.</p>



<h2 class="wp-block-heading"><strong>Best Practices to Protect Against Phishing</strong></h2>



<p>Organizations and individuals can significantly reduce phishing risks by following these security practices:</p>



<ul class="wp-block-list">
<li>Enable Multi-Factor Authentication (MFA).</li>



<li>Use strong and unique passwords for every account.</li>



<li>Keep operating systems and applications up to date.</li>



<li>Verify unexpected requests before responding.</li>



<li>Avoid opening unknown attachments or clicking suspicious links.</li>



<li>Use email security filtering solutions.</li>



<li>Conduct regular cybersecurity awareness training.</li>



<li>Report suspected phishing emails to your IT or security team.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Phishing attacks continue to evolve, becoming more sophisticated and difficult to detect. However, most successful attacks still rely on users overlooking common warning signs.</p>



<p>By carefully verifying email senders, avoiding suspicious links and attachments, and following cybersecurity best practices, individuals and organizations can greatly reduce their exposure to phishing attacks and protect sensitive information from cybercriminals.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/top-10-phishing-email-red-flags/">Top 10 Phishing Email Red Flags You Should Never Ignore</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/top-10-phishing-email-red-flags/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fake Roblox Hacks Target Discord and Gaming Credentials</title>
		<link>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/</link>
					<comments>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 20:49:48 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[discord]]></category>
		<category><![CDATA[Gaming Security]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Java RAT]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[remote access trojan]]></category>
		<category><![CDATA[Roblox]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Xeno Cheat]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12135</guid>

					<description><![CDATA[<p>Security researchers have uncovered an ongoing malware campaign that uses fake Roblox Xeno cheat tools to infect gamers</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/">Fake Roblox Hacks Target Discord and Gaming Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have uncovered an ongoing malware campaign that uses <strong>fake Roblox Xeno cheat tools</strong> to infect gamers with a powerful <strong>Java-based Remote Access Trojan (RAT)</strong>.</p>



<p>The attackers are primarily targeting users through <strong>Discord servers</strong> and gaming forums, where fake cheat downloads are shared as legitimate software. By taking advantage of the popularity of Roblox cheats, the campaign aims to steal sensitive information and gain complete control of victims&#8217; computers.</p>



<p>Researchers say the operation continues to evolve, with new infrastructure and malware capabilities being added regularly.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>The infection starts when users download what appears to be a genuine <strong>Xeno Roblox cheat</strong>.</p>



<p>The downloaded archive looks convincing, containing realistic folder structures and harmless-looking files that make it appear authentic.</p>



<p>Instead of launching a game cheat, the installer quietly begins executing malicious code in the background.</p>



<p>If Java is not already installed on the system, the malware automatically installs a local Java Runtime Environment without the user&#8217;s knowledge. This prepares the system for the next stage of the attack.</p>



<h2 class="wp-block-heading"><strong>Multi-Stage Malware Deployment</strong></h2>



<p>After the initial infection, the malware loads a heavily obfuscated Java application disguised as a normal Windows executable.</p>



<p>Before continuing, it performs several checks to determine whether it is running inside a virtual machine, sandbox, or debugging environment. These techniques help attackers avoid detection by security researchers.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<p>The malware then collects basic system information and securely communicates with its command-and-control (C2) server to register the infected device and download additional malicious components.</p>



<h2 class="wp-block-heading"><strong>Java RAT Gains Full System Access</strong></h2>



<p>The final payload is a <strong>Java Remote Access Trojan (RAT)</strong> hidden inside folders designed to resemble legitimate Microsoft GameDVR files associated with the Xbox Game Bar.</p>



<p>To remain active after a reboot, the malware creates registry <strong>Run</strong> entries using names that appear to be legitimate Windows components. It also attempts to obtain elevated privileges, allowing it to perform more advanced malicious activities.</p>



<p>Once established, the RAT connects to attacker-controlled servers and waits for further instructions.</p>



<h2 class="wp-block-heading"><strong>What Information Does the Malware Target?</strong></h2>



<p>Unlike basic information-stealing malware, this campaign combines credential theft with powerful remote surveillance features.</p>



<p>The malware is capable of:</p>



<ul class="wp-block-list">
<li>Stealing saved passwords and browser cookies.</li>



<li>Collecting credentials from Chrome, Edge, Opera, and Brave.</li>



<li>Hijacking Discord, Roblox, and Minecraft accounts.</li>



<li>Targeting cryptocurrency wallets, including Exodus.</li>



<li>Capturing keystrokes and mouse activity.</li>



<li>Taking screenshots.</li>



<li>Streaming the victim&#8217;s desktop.</li>



<li>Accessing webcam feeds.</li>



<li>Uploading, downloading, and modifying files.</li>



<li>Running PowerShell commands.</li>



<li>Providing attackers with remote shell access.</li>
</ul>



<p>These capabilities allow attackers to fully control an infected computer while collecting valuable personal and financial information.</p>



<h2 class="wp-block-heading"><strong>Why Gamers Are Being Targeted</strong></h2>



<p>Researchers believe the campaign specifically targets Roblox players because many users search online for &#8220;free&#8221; or &#8220;undetected&#8221; cheat tools.</p>



<p>Young gamers are especially at risk, as they may download unofficial software from Discord communities or third-party websites without realizing it contains malware.</p>



<p>Since many gaming PCs are shared with family members, a successful infection could also expose banking information, personal documents, saved passwords, and private communications stored on the same device.</p>



<h2 class="wp-block-heading"><strong>Malware Campaign Continues to Evolve</strong></h2>



<p>Security researchers, including <strong>Bitdefender</strong> and previous investigations by <strong>ThreatLocker</strong>, have linked the campaign to malware previously tracked as <strong>Powercat</strong>.</p>



<p>The operation has reportedly been active since early 2026 and continues to expand through new command-and-control servers and updated malware modules. The attackers also use encrypted communications and in-memory payload execution, making the malware more difficult to detect and remove.</p>



<h2 class="wp-block-heading"><strong>How to Stay Protected</strong></h2>



<p>To reduce the risk of infection, users should follow these security best practices:</p>



<ul class="wp-block-list">
<li>Avoid downloading unofficial Roblox cheats or game modification tools.</li>



<li>Only install software from trusted sources.</li>



<li>Keep antivirus and security software up to date.</li>



<li>Enable multi-factor authentication (MFA) on gaming and email accounts.</li>



<li>Regularly update Windows and installed applications.</li>



<li>Be cautious of download links shared through Discord servers or online gaming forums.</li>
</ul>



<p>As cybercriminals increasingly target gaming communities, staying away from unofficial cheat software remains one of the most effective ways to avoid malware infections and protect personal information.</p>



<h2 class="wp-block-heading" id="h-iocs"><strong>IOCs</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>MD5</strong><strong></strong></td><td colspan="2"><strong>Description</strong><strong></strong></td></tr><tr><td>4bdaf7792e908f163ebef137854c571d</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>9930036e8f787674db39094e21413e77</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>9699bd6a448d0662a1e9e353223263b6</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>1a462c76efc4e73725b9e95c4a00fddb</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>7b96170259a376ea79411c5713beb396</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>2ead73ed62f1c2beb9043ce92e774e0b</td><td colspan="2">malicious xeno.exe loader</td></tr><tr><td>0aadd62b535e683a5a2fe31fde546d07</td><td colspan="2">malicious xeno.exe loader</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/">Fake Roblox Hacks Target Discord and Gaming Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Threat Analysis: DarkSword Framework Leverages iOS Exploits for Apple ID Harvesting</title>
		<link>https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/</link>
					<comments>https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 05:16:00 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Apple ID Phishing]]></category>
		<category><![CDATA[Apple security]]></category>
		<category><![CDATA[C2 Server]]></category>
		<category><![CDATA[credential theft]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DarkSword]]></category>
		<category><![CDATA[iOS Exploit]]></category>
		<category><![CDATA[iOS Malware]]></category>
		<category><![CDATA[iPhone Security]]></category>
		<category><![CDATA[iPhone Vulnerability]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[Safari Exploit]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12130</guid>

					<description><![CDATA[<p>DarkSword, a powerful iPhone exploit kit whose source code was leaked online, is now being used by multiple</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/">Threat Analysis: DarkSword Framework Leverages iOS Exploits for Apple ID Harvesting</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>DarkSword, a powerful iPhone exploit kit whose source code was leaked online, is now being used by multiple threat actors to launch large-scale cyberattacks. The latest campaigns combine one-click Safari exploits with fake Apple ID login pages, allowing attackers to steal credentials and compromise iPhones in a single attack.</p>



<p>The exploit chain was originally discovered by Google Threat Intelligence Group, iVerify, and Lookout. After the complete JavaScript-based toolkit was leaked on GitHub, several unrelated attackers began reusing the same code instead of creating their own versions.</p>



<p>Researchers found that at least seven threat groups are now operating DarkSword infrastructure. The attackers use identical exploit files, matching code hashes, and even the same Russian-language comments found in the leaked source code, confirming they are all relying on the leaked toolkit.</p>



<p>One of the newest operators appears to be a Chinese-speaking threat actor managing more than 100 malicious websites across Hong Kong, Japan, the United States, and several European countries. Earlier campaigns mainly used fake AWS login pages, but researchers have now identified Apple ID phishing pages hosted on the same servers that deliver the DarkSword exploit.</p>



<h2 class="wp-block-heading"><strong>How the DarkSword Campaign Works</strong></h2>



<p>Researchers tracked the attackers by comparing file hashes and exploit pages instead of relying only on domains or IP addresses, which change frequently. This method helped identify additional DarkSword infrastructure that traditional detection methods had missed.</p>



<p>According to Censys, the campaign continues to grow as attackers regularly move their infrastructure to new hosting providers and domains.</p>



<p>Researchers identified several key characteristics of the operation:</p>



<ul class="wp-block-list">
<li>Multiple DarkSword administration panels hosted in Hong Kong, Japan, and the United States.</li>



<li>Chinese-language login panels running on ports such as 3000, 8443, and 8888.</li>



<li>Fake Apple ID login pages hosted on the same servers as the exploit chain.</li>



<li>Identical exploit files and malware modules reused across different operators.</li>



<li>Infrastructure spread across multiple hosting providers to avoid easy detection.</li>
</ul>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<h2 class="wp-block-heading"><strong>What Happens After an iPhone Is Compromised?</strong></h2>



<p>One of the most dangerous changes in this campaign is the combination of Apple ID phishing pages with DarkSword&#8217;s exploit delivery. Victims believe they are signing in to a legitimate Apple account, while hidden exploit code is loaded in the background through Safari.</p>



<p>Security researchers say DarkSword chains multiple iOS vulnerabilities affecting WebKit, the GPU, the dynamic linker, and the kernel to gain deep access to vulnerable devices.</p>



<p>After a successful compromise, the malware can:</p>



<ul class="wp-block-list">
<li>Steal Apple Keychain passwords and saved credentials.</li>



<li>Extract iCloud account information.</li>



<li>Collect saved Wi-Fi passwords.</li>



<li>Download files stored on the device.</li>



<li>Send stolen data to attacker-controlled command-and-control (C2) servers.</li>
</ul>



<p>Researchers also found that most DarkSword deployments use identical malware files, showing attackers are directly reusing the leaked toolkit instead of developing new versions. Although many servers are hosted in Hong Kong, the infrastructure is distributed across several internet providers, making IP-based blocking less effective.</p>



<p>Additional evidence, including Chinese-language control panels, references to an &#8220;Asia-Pacific Group,&#8221; and a Telegram contact, suggests the latest infrastructure is operated by a Chinese-speaking threat actor. However, researchers say there is not yet enough evidence to confidently attribute the campaign to a specific group.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/">Threat Analysis: DarkSword Framework Leverages iOS Exploits for Apple ID Harvesting</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Vulnerability Disclosed in VS Code, Cursor, and Google Antigravity</title>
		<link>https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/</link>
					<comments>https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 05:04:10 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[Code Editors]]></category>
		<category><![CDATA[Cursor]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Developer Security]]></category>
		<category><![CDATA[Google Antigravity]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VS Code]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12125</guid>

					<description><![CDATA[<p>A recently patched security vulnerability exposed three popular code editors—Microsoft VS Code, Cursor, and Google Antigravity—to a serious</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/">Critical Vulnerability Disclosed in VS Code, Cursor, and Google Antigravity</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A recently patched security vulnerability exposed three popular code editors—<strong>Microsoft VS Code, Cursor, and Google Antigravity</strong>—to a serious <strong>remote code execution (RCE)</strong> risk.</p>



<p>According to security researchers at <strong>AISLE</strong>, the flaw could have allowed attackers to compromise a developer&#8217;s system simply by convincing them to click a malicious link embedded in a Git commit message.</p>



<p>The issue has now been fixed across all affected platforms, but it highlights the growing security risks facing modern AI-powered development tools.</p>



<h2 class="wp-block-heading">How the Attack Worked</h2>



<p>The vulnerability relied on a malicious link hidden inside a Git commit message.</p>



<p>If a developer clicked the link while viewing the commit inside one of the affected editors, arbitrary code could run automatically with the same permissions as the developer.</p>



<p>The attack required only a single click and did not display any warning, confirmation message, or security prompt, making the compromise difficult to notice.</p>



<h2 class="wp-block-heading">What Attackers Could Do</h2>



<p>Successful exploitation could have given attackers extensive control over a developer&#8217;s machine.</p>



<p>Potential impacts included:</p>



<ul class="wp-block-list">
<li>Stealing API keys and other sensitive credentials.</li>



<li>Installing malware or keyloggers.</li>



<li>Accessing, modifying, or deleting local files.</li>



<li>Maintaining persistent access even after the editor was closed.</li>
</ul>



<p>Because the malicious activity could remain hidden, developers might not realize their systems had been compromised.</p>



<h2 class="wp-block-heading">Vulnerability Found Across Multiple Editors</h2>



<p>AISLE first discovered the flaw in <strong>Microsoft VS Code</strong> during security testing in late 2025.</p>



<p>Since <strong>Cursor</strong> is built on the VS Code codebase, it inherited the same vulnerability. Later, researchers identified the identical issue in <strong>Google Antigravity</strong>, another AI-assisted coding environment based on the same architecture.</p>



<p>The discovery shows how a single vulnerability in a shared codebase can spread across multiple developer tools used by millions of people.</p>



<h2 class="wp-block-heading">Vendors Released Security Fixes</h2>



<p>After receiving responsible disclosure reports, all three vendors addressed the issue.</p>



<ul class="wp-block-list">
<li>Cursor released a security update shortly after notification.</li>



<li>Google patched the vulnerability in Antigravity within days.</li>



<li>Microsoft later released a fix for VS Code.</li>
</ul>



<p>Current versions of all three editors are no longer affected.</p>



<h2 class="wp-block-heading">Why This Matters</h2>



<p>Many modern AI coding tools are developed using common open-source foundations such as VS Code. While this speeds up development and feature delivery, it also means a single security flaw can impact multiple products simultaneously.</p>



<p>This incident demonstrates the importance of continuous security testing and timely patch management, particularly for AI-powered development environments.</p>



<h2 class="wp-block-heading">What Developers Should Do</h2>



<p>Developers and organizations should take the following steps:</p>



<ul class="wp-block-list">
<li>Update VS Code, Cursor, or Google Antigravity to the latest version.</li>



<li>Review recent Git activity for anything suspicious.</li>



<li>Rotate API keys and credentials if older vulnerable versions were used.</li>



<li>Monitor developer systems for unusual behavior or unauthorized access.</li>
</ul>



<p>Keeping development tools fully updated and regularly reviewing credentials can help reduce the risk of future software supply chain attacks.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/">Critical Vulnerability Disclosed in VS Code, Cursor, and Google Antigravity</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Takes Action to Strengthen NuGet Supply Chain Security</title>
		<link>https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/</link>
					<comments>https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 04:56:04 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[.net]]></category>
		<category><![CDATA[api keys]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[NuGet]]></category>
		<category><![CDATA[OIDC]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[supply chain security]]></category>
		<category><![CDATA[Trusted Publishing]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12120</guid>

					<description><![CDATA[<p>Microsoft has announced important security updates for NuGet.org aimed at improving software supply chain security and reducing the</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/">Microsoft Takes Action to Strengthen NuGet Supply Chain Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft has announced important security updates for <strong>NuGet.org</strong> aimed at improving software supply chain security and reducing the risk of compromised developer credentials being used to distribute malicious .NET packages.</p>



<p>Under the new policy, <strong>API keys created on or after August 17, 2026, will have a maximum lifetime of 30 days</strong>. Developers will no longer be able to create API keys that remain valid for 365 days. In addition, <strong>all API keys generated before August 17, 2026, will automatically expire on November 1, 2026</strong>.</p>



<p>The move is part of Microsoft&#8217;s broader effort to strengthen package security and encourage developers to adopt more secure authentication methods.</p>



<h2 class="wp-block-heading">Why Is Microsoft Reducing API Key Lifetimes?</h2>



<p>NuGet API keys are used by developers to publish packages to NuGet.org. These keys often function like passwords and are commonly stored in CI/CD pipelines, build servers, repository secrets, deployment environments, and other automation platforms.</p>



<p>Although this makes automated package publishing easier, it also creates an attractive target for cybercriminals. If attackers gain access to a long-lived API key, they could publish malicious packages under the name of a trusted project without immediately being detected.</p>



<p>By limiting API keys to just 30 days, Microsoft aims to significantly reduce the period during which a stolen credential can be exploited.</p>



<h2 class="wp-block-heading">The Growing Risk of Supply Chain Attacks</h2>



<p>Software supply chain attacks continue to rise as attackers increasingly target trusted software repositories instead of individual users.</p>



<p>Rather than directly attacking organizations, threat actors compromise developer credentials or package publishing accounts to insert malicious code into legitimate software packages. Once published, these compromised packages may be downloaded by thousands of developers and organizations, allowing malware to spread rapidly across multiple environments.</p>



<p>Microsoft explained that reducing the lifespan of publishing credentials is an important step toward minimizing this risk.</p>



<h2 class="wp-block-heading">Recent Incidents Highlight the Threat</h2>



<p>Microsoft referenced recent software package compromise incidents that demonstrate the dangers of stolen publishing credentials.</p>



<p>One notable example involved the <strong>NX Console</strong> package in the npm ecosystem. Attackers reportedly obtained valid publishing credentials and used them to release a malicious version of the package.</p>



<p>The compromised package was activated approximately <strong>6,000 times within just 36 minutes</strong> before it was removed. This incident showed how quickly attackers can exploit trusted software repositories when publishing credentials fall into the wrong hands.</p>



<p>Events like these continue to reinforce the need for stronger authentication and shorter-lived credentials across software ecosystems.</p>



<h2 class="wp-block-heading">Shorter API Keys Improve Security—but Don&#8217;t Eliminate the Risk</h2>



<p>While reducing API key validity lowers the window of opportunity for attackers, Microsoft emphasized that shorter expiration periods alone cannot completely prevent credential theft.</p>



<p>API keys can still be exposed through several common scenarios, including:</p>



<ul class="wp-block-list">
<li>Source code repositories</li>



<li>CI/CD pipeline logs</li>



<li>Insecure secret storage</li>



<li>Build servers</li>



<li>Compromised developer workstations</li>



<li>Accidentally shared configuration files</li>
</ul>



<p>If an attacker obtains an active API key, they may still be able to publish malicious packages before the credential expires.</p>



<p>For this reason, Microsoft is encouraging developers to move beyond traditional API keys altogether.</p>



<h2 class="wp-block-heading">Microsoft Recommends NuGet Trusted Publishing</h2>



<p>To provide a more secure publishing process, Microsoft recommends using <strong>NuGet Trusted Publishing</strong>, which became available in September 2025.</p>



<p>Trusted Publishing replaces long-lived API keys with <strong>OpenID Connect (OIDC)</strong> authentication, allowing CI/CD platforms to securely verify their identity without permanently storing publishing credentials.</p>



<p>Instead of relying on reusable secrets, supported CI/CD services generate a temporary identity token during the publishing workflow.</p>



<p>NuGet.org validates this token against security policies configured by the package owner before issuing a temporary publishing credential that is valid only for that specific publishing operation.</p>



<p>This approach greatly reduces the chances of stolen credentials being reused by attackers.</p>



<h2 class="wp-block-heading">How Trusted Publishing Works</h2>



<p>The Trusted Publishing workflow is designed to eliminate long-lived secrets from automated publishing environments.</p>



<p>The process works as follows:</p>



<ol class="wp-block-list">
<li>A supported CI/CD platform generates a short-lived OIDC identity token.</li>



<li>NuGet.org verifies the identity of the workflow.</li>



<li>Repository, workflow, and optional environment details are validated against the package owner&#8217;s security policy.</li>



<li>NuGet.org issues a temporary API key for that publishing session.</li>



<li>Once the publishing job is complete, the temporary credential expires automatically.</li>
</ol>



<p>Because no reusable API key is stored in repositories or CI/CD secrets, attackers have far fewer opportunities to steal publishing credentials.</p>



<h2 class="wp-block-heading">Benefits of Trusted Publishing</h2>



<p>Microsoft highlighted several advantages of adopting Trusted Publishing:</p>



<ul class="wp-block-list">
<li>Eliminates long-lived API keys.</li>



<li>Reduces the risk of credential theft.</li>



<li>Removes the need to store publishing secrets in repositories.</li>



<li>Simplifies credential rotation.</li>



<li>Improves software supply chain security.</li>



<li>Limits the impact of compromised developer environments.</li>



<li>Strengthens automated package publishing workflows.</li>
</ul>



<p>GitHub Actions and GitLab users are encouraged to migrate to Trusted Publishing before the August 2026 deadline.</p>



<h2 class="wp-block-heading">What Developers Should Do Before the Deadline</h2>



<p>Organizations that continue using traditional NuGet API keys should begin preparing now.</p>



<p>Microsoft recommends the following actions:</p>



<ul class="wp-block-list">
<li>Review all NuGet publishing workflows.</li>



<li>Identify API keys created before August 17, 2026.</li>



<li>Update automation to support 30-day API key rotation.</li>



<li>Restrict API keys to the minimum required package scope.</li>



<li>Apply the least-privilege principle for publishing permissions.</li>



<li>Avoid storing API keys in source code, configuration files, or logs.</li>



<li>Immediately revoke any API key that may have been exposed.</li>



<li>Begin migrating CI/CD pipelines to Trusted Publishing wherever possible.</li>
</ul>



<p>Taking these steps can help reduce the risk of malicious package publishing while ensuring a smooth transition to the new policy.</p>



<h2 class="wp-block-heading">Looking Ahead</h2>



<p>Microsoft indicated that shortening API key lifetimes is only one phase of its long-term software supply chain security strategy. As support for Trusted Publishing expands across additional CI/CD platforms, the company may further reduce API key validity periods in the future.</p>



<p>Developers and organizations are encouraged to adopt modern authentication methods such as OpenID Connect to strengthen package security, reduce reliance on reusable secrets, and better protect the software supply chain against evolving cyber threats.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/">Microsoft Takes Action to Strengthen NuGet Supply Chain Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
