<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybercriminals &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/cybercriminals/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Wed, 12 Aug 2026 16:54:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Cybercriminals &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>WhatsApp Scam Alert: New Protection Against Hackers</title>
		<link>https://firsthackersnews.com/whatsapp-scam-alert-feature/</link>
					<comments>https://firsthackersnews.com/whatsapp-scam-alert-feature/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 16:54:49 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[AI security]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Messaging Security]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Online scams]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Scam Alert]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12190</guid>

					<description><![CDATA[<p>WhatsApp has introduced a new optional feature called Scam Alert to help users identify potentially fraudulent messages while</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-scam-alert-feature/">WhatsApp Scam Alert: New Protection Against Hackers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp has introduced a new optional feature called <strong>Scam Alert</strong> to help users identify potentially fraudulent messages while keeping its end-to-end encryption intact.</p>



<p>The feature is designed to address the growing use of more convincing scams, including messages created with the help of AI. Instead of sending messages to WhatsApp’s servers for analysis, Scam Alert uses a small machine learning model that runs directly on the user’s device.</p>



<p>Once enabled, the model examines messages from people who are not saved as contacts. It looks for patterns in the conversation and language that may indicate common scam techniques.</p>



<p>The message itself stays on the device during this process. WhatsApp says it does not automatically send messages to Meta, WhatsApp, or another third party for review. Users decide what happens next.</p>



<p>If a message appears suspicious, WhatsApp can display a warning to the recipient. The user can then choose to <strong>block the sender, report the conversation, continue chatting, or mark the conversation as trusted</strong> if they believe the warning is incorrect.</p>



<h3 class="wp-block-heading">Privacy Is a Key Part of Scam Alert</h3>



<p>WhatsApp says the system was designed around three main ideas: <strong>local processing, no automatic reporting, and user control</strong>.</p>



<p>The company still needs some information to understand how well the feature performs. Instead of collecting individual messages, WhatsApp uses a privacy-focused analytics system that gathers limited information such as how many warnings were displayed and what actions users took.</p>



<p>This information is processed using <strong>Trusted Execution Environments (TEEs)</strong> and additional privacy techniques before aggregated statistics are sent to Meta.</p>



<h3 class="wp-block-heading">Protecting the AI Model</h3>



<p>Another concern is making sure attackers cannot secretly deliver a modified version of the scam-detection model to specific users.</p>



<p>WhatsApp says each model version is published with a <strong>SHA-256 hash</strong> in an append-only transparency system before it is deployed. This creates a record that can be used to verify that the model has not been secretly changed.</p>



<p>Model downloads also use an <strong>Oblivious HTTP (OHTTP) relay</strong>, which helps prevent the server from directly linking a model request to a user&#8217;s IP address.</p>



<p>WhatsApp says even the process used to assign users to different model versions for testing happens locally on their devices rather than being controlled by the server.</p>



<h3 class="wp-block-heading">Additional Security Controls</h3>



<p>The company says Scam Alert was designed to protect against several types of threats, including outside attackers, malicious employees, and compromised third-party suppliers.</p>



<p>Its security measures include isolated confidential computing environments, encrypted memory, and additional protections around the systems running the analytics infrastructure.</p>



<p>Users can also check information about the feature through WhatsApp&#8217;s transparency controls. The in-app activity section shows details such as which messages were analyzed and which model version was used.</p>



<h3 class="wp-block-heading">External Researchers Can Test the System</h3>



<p>WhatsApp is also expanding its <strong>Bug Bounty program</strong> to cover parts of the Scam Alert technology, including the machine learning models and analytics infrastructure.</p>



<p>This gives security researchers an opportunity to look for weaknesses and verify whether the system is being used only for its stated purpose of detecting scams.</p>



<h3 class="wp-block-heading">Limited Beta Release</h3>



<p>Scam Alert is initially being introduced through a <strong>limited beta rollout</strong>. WhatsApp says it plans to continue testing the technology with security researchers before making it more widely available.</p>



<p>The company also plans to publish a technical white paper explaining how the system works in greater detail.</p>



<p>The approach reflects a growing focus on building AI-powered security features without giving up user privacy. Instead of sending private conversations to the cloud for analysis, WhatsApp is attempting to combine <strong>on-device AI, confidential computing, and transparency mechanisms</strong> to detect scams while keeping message content protected.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-scam-alert-feature/">WhatsApp Scam Alert: New Protection Against Hackers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-scam-alert-feature/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>LLM API Bugs Leak Hidden Reasoning Traces</title>
		<link>https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/</link>
					<comments>https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 22:08:32 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[AI security]]></category>
		<category><![CDATA[AI Vulnerability]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[api security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Google Gemini]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[openAI]]></category>
		<category><![CDATA[Prompt Injection]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12186</guid>

					<description><![CDATA[<p>A new security research report has uncovered a serious weakness in the way major AI providers protect the</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/">LLM API Bugs Leak Hidden Reasoning Traces</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A new security research report has uncovered a serious weakness in the way major AI providers protect the hidden reasoning generated by their large language models.</p>



<p>The research involves <strong>OpenAI, Anthropic, and Google</strong>, and shows that encrypted reasoning data produced by powerful models could potentially be reused with less restricted models from the same provider. In some cases, this could allow the hidden reasoning to be reconstructed in readable text.</p>



<p>Researchers from the <strong>ELLIS Institute Tübingen, Max Planck Institute, MATS Research, and Snyk</strong> investigated the issue across the Claude, GPT, and Gemini ecosystems. The attack does not require special privileges and can be carried out through normal API access.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>Modern reasoning models perform additional processing before producing their final answers. Much of this internal reasoning is intentionally hidden from users because it may contain sensitive information, system instructions, safety-related decisions, or proprietary model behavior.</p>



<p>Instead of keeping all conversation state on the server, some AI APIs return encrypted data that can be sent back with later requests. This allows the model to continue a conversation without storing every detail on the provider&#8217;s side.</p>



<p>Researchers found a potential weakness in how these encrypted reasoning packages were protected.</p>



<p>The data was not sufficiently tied to the <strong>specific model, user, or session</strong> that originally created it. This meant a reasoning package generated by a more heavily protected model could potentially be submitted to another model within the same provider&#8217;s ecosystem.</p>



<h2 class="wp-block-heading"><strong>Using Smaller Models to Reveal Hidden Data</strong></h2>



<p>The researchers demonstrated an attack technique in which a reasoning package from a powerful model was passed to a less restricted model.</p>



<p>The smaller model could then be prompted to reproduce information contained inside the encrypted package.</p>



<p>This creates an unusual security problem. The attacker does not necessarily need to break the encryption directly. Instead, another model can potentially act as an intermediary that helps expose the information.</p>



<p>The research team reported similar behavior across the <strong>GPT, Claude, and Gemini</strong> model families.</p>



<p>Researchers also compared the recovered reasoning data with usage information provided through the APIs to determine whether the extracted material corresponded to the original reasoning process.</p>



<h2 class="wp-block-heading"><strong>Hidden Reasoning Can Contain Sensitive Information</strong></h2>



<p>The concern goes beyond exposing how an AI model thinks.</p>



<p>Researchers analyzed thousands of publicly available AI agent transcripts collected from sources such as GitHub and Hugging Face. Their analysis identified hundreds of pieces of potentially sensitive information inside recovered reasoning data.</p>



<p>This included:</p>



<ul class="wp-block-list">
<li><strong>367</strong> pieces of personally identifiable information</li>



<li><strong>182</strong> hardcoded credentials</li>



<li><strong>62</strong> API keys</li>



<li><strong>33</strong> passwords</li>



<li><strong>30</strong> personal email addresses</li>
</ul>



<p>The problem is that some of this information may never appear in the model&#8217;s visible response.</p>



<p>A developer could therefore publish an AI session or agent log believing it contains no secrets, while sensitive information remains hidden inside associated reasoning data.</p>



<h2 class="wp-block-heading"><strong>A New Risk for AI Agents</strong></h2>



<p>The research also highlights a potential problem for autonomous AI systems.</p>



<p>If security monitoring only examines the visible conversation between a user and an AI agent, malicious instructions hidden inside reasoning-related data could potentially escape detection.</p>



<p>An attacker could attempt to place instructions inside an encrypted reasoning package and have those instructions processed later by an AI agent.</p>



<p>This creates a potential <strong>indirect prompt injection</strong> scenario where the malicious content is not obvious in the conversation that security tools are monitoring.</p>



<p>For organizations using AI agents to interact with cloud services, databases, code repositories, or business applications, this type of hidden input deserves particular attention.</p>



<h2 class="wp-block-heading"><strong>Which AI Platforms Were Studied?</strong></h2>



<p>The research covered major model ecosystems from three providers:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th><strong>Provider</strong></th><th><strong>Models Studied</strong></th><th><strong>Potential Risk</strong></th></tr><tr><td><strong>Anthropic</strong></td><td>Claude family</td><td>Hidden reasoning, system prompts, credentials</td></tr><tr><td><strong>OpenAI</strong></td><td>GPT family</td><td>Reasoning data, safety information, sensitive content</td></tr><tr><td><strong>Google</strong></td><td>Gemini family</td><td>Secrets, hidden instructions, and personal information</td></tr></tbody></table></figure>



<p>The exact attack paths and model combinations varied between providers, but the broader issue was similar: <strong>reasoning data was not sufficiently isolated from other models within the same ecosystem</strong>.</p>



<h2 class="wp-block-heading"><strong>Providers Have Already Responded</strong></h2>



<p>The researchers reported the findings to the affected companies through responsible disclosure.</p>



<p><strong>OpenAI, Anthropic, and Google acknowledged the research and introduced server-side protections.</strong> According to the researchers, the original proof-of-concept attacks could no longer be reproduced against the updated API implementations.</p>



<p>That reduces the immediate risk from the specific attack demonstrated in the research, but the findings highlight a larger issue for the AI industry.</p>



<p>As AI systems become more complex, security controls need to protect not only visible prompts and responses but also the internal data exchanged between models and supporting services.</p>



<h2 class="wp-block-heading"><strong>How Organizations Can Reduce the Risk</strong></h2>



<p>AI providers and companies building applications around LLMs can take several steps to protect sensitive reasoning-related data.</p>



<p><strong>Bind encrypted data to its source.</strong> Reasoning packages should be cryptographically linked to the specific model, user, and session that created them.</p>



<p><strong>Separate model tiers.</strong> A payload generated by one model should not automatically be accepted by another model unless that behavior is explicitly intended and securely controlled.</p>



<p><strong>Rotate older cryptographic keys.</strong> Where historical encrypted data may have been exposed, organizations should consider key rotation and invalidation strategies.</p>



<p><strong>Protect AI logs.</strong> Developers should treat reasoning-related payloads, signatures, and encrypted model data as sensitive information. These fields should be removed or sanitized before logs are shared publicly.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>The research shows that protecting AI systems is not only about securing the model itself.</p>



<p>Modern LLM platforms involve APIs, model tiers, encrypted payloads, agent frameworks, logging systems, and multiple supporting services. A weakness in the connection between these components can create a security problem even when the underlying model remains protected.</p>



<p>For organizations adopting AI agents and reasoning models, the lesson is clear: <strong>hidden data should be treated as sensitive data, even when users cannot see it.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/">LLM API Bugs Leak Hidden Reasoning Traces</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/llm-api-vulnerability-hidden-reasoning/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fake Roblox Hacks Target Discord and Gaming Credentials</title>
		<link>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/</link>
					<comments>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 20:49:48 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[discord]]></category>
		<category><![CDATA[Gaming Security]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Java RAT]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[remote access trojan]]></category>
		<category><![CDATA[Roblox]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Xeno Cheat]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12135</guid>

					<description><![CDATA[<p>Security researchers have uncovered an ongoing malware campaign that uses fake Roblox Xeno cheat tools to infect gamers</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/">Fake Roblox Hacks Target Discord and Gaming Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have uncovered an ongoing malware campaign that uses <strong>fake Roblox Xeno cheat tools</strong> to infect gamers with a powerful <strong>Java-based Remote Access Trojan (RAT)</strong>.</p>



<p>The attackers are primarily targeting users through <strong>Discord servers</strong> and gaming forums, where fake cheat downloads are shared as legitimate software. By taking advantage of the popularity of Roblox cheats, the campaign aims to steal sensitive information and gain complete control of victims&#8217; computers.</p>



<p>Researchers say the operation continues to evolve, with new infrastructure and malware capabilities being added regularly.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>The infection starts when users download what appears to be a genuine <strong>Xeno Roblox cheat</strong>.</p>



<p>The downloaded archive looks convincing, containing realistic folder structures and harmless-looking files that make it appear authentic.</p>



<p>Instead of launching a game cheat, the installer quietly begins executing malicious code in the background.</p>



<p>If Java is not already installed on the system, the malware automatically installs a local Java Runtime Environment without the user&#8217;s knowledge. This prepares the system for the next stage of the attack.</p>



<h2 class="wp-block-heading"><strong>Multi-Stage Malware Deployment</strong></h2>



<p>After the initial infection, the malware loads a heavily obfuscated Java application disguised as a normal Windows executable.</p>



<p>Before continuing, it performs several checks to determine whether it is running inside a virtual machine, sandbox, or debugging environment. These techniques help attackers avoid detection by security researchers.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<p>The malware then collects basic system information and securely communicates with its command-and-control (C2) server to register the infected device and download additional malicious components.</p>



<h2 class="wp-block-heading"><strong>Java RAT Gains Full System Access</strong></h2>



<p>The final payload is a <strong>Java Remote Access Trojan (RAT)</strong> hidden inside folders designed to resemble legitimate Microsoft GameDVR files associated with the Xbox Game Bar.</p>



<p>To remain active after a reboot, the malware creates registry <strong>Run</strong> entries using names that appear to be legitimate Windows components. It also attempts to obtain elevated privileges, allowing it to perform more advanced malicious activities.</p>



<p>Once established, the RAT connects to attacker-controlled servers and waits for further instructions.</p>



<h2 class="wp-block-heading"><strong>What Information Does the Malware Target?</strong></h2>



<p>Unlike basic information-stealing malware, this campaign combines credential theft with powerful remote surveillance features.</p>



<p>The malware is capable of:</p>



<ul class="wp-block-list">
<li>Stealing saved passwords and browser cookies.</li>



<li>Collecting credentials from Chrome, Edge, Opera, and Brave.</li>



<li>Hijacking Discord, Roblox, and Minecraft accounts.</li>



<li>Targeting cryptocurrency wallets, including Exodus.</li>



<li>Capturing keystrokes and mouse activity.</li>



<li>Taking screenshots.</li>



<li>Streaming the victim&#8217;s desktop.</li>



<li>Accessing webcam feeds.</li>



<li>Uploading, downloading, and modifying files.</li>



<li>Running PowerShell commands.</li>



<li>Providing attackers with remote shell access.</li>
</ul>



<p>These capabilities allow attackers to fully control an infected computer while collecting valuable personal and financial information.</p>



<h2 class="wp-block-heading"><strong>Why Gamers Are Being Targeted</strong></h2>



<p>Researchers believe the campaign specifically targets Roblox players because many users search online for &#8220;free&#8221; or &#8220;undetected&#8221; cheat tools.</p>



<p>Young gamers are especially at risk, as they may download unofficial software from Discord communities or third-party websites without realizing it contains malware.</p>



<p>Since many gaming PCs are shared with family members, a successful infection could also expose banking information, personal documents, saved passwords, and private communications stored on the same device.</p>



<h2 class="wp-block-heading"><strong>Malware Campaign Continues to Evolve</strong></h2>



<p>Security researchers, including <strong>Bitdefender</strong> and previous investigations by <strong>ThreatLocker</strong>, have linked the campaign to malware previously tracked as <strong>Powercat</strong>.</p>



<p>The operation has reportedly been active since early 2026 and continues to expand through new command-and-control servers and updated malware modules. The attackers also use encrypted communications and in-memory payload execution, making the malware more difficult to detect and remove.</p>



<h2 class="wp-block-heading"><strong>How to Stay Protected</strong></h2>



<p>To reduce the risk of infection, users should follow these security best practices:</p>



<ul class="wp-block-list">
<li>Avoid downloading unofficial Roblox cheats or game modification tools.</li>



<li>Only install software from trusted sources.</li>



<li>Keep antivirus and security software up to date.</li>



<li>Enable multi-factor authentication (MFA) on gaming and email accounts.</li>



<li>Regularly update Windows and installed applications.</li>



<li>Be cautious of download links shared through Discord servers or online gaming forums.</li>
</ul>



<p>As cybercriminals increasingly target gaming communities, staying away from unofficial cheat software remains one of the most effective ways to avoid malware infections and protect personal information.</p>



<h2 class="wp-block-heading" id="h-iocs"><strong>IOCs</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>MD5</strong><strong></strong></td><td colspan="2"><strong>Description</strong><strong></strong></td></tr><tr><td>4bdaf7792e908f163ebef137854c571d</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>9930036e8f787674db39094e21413e77</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>9699bd6a448d0662a1e9e353223263b6</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>1a462c76efc4e73725b9e95c4a00fddb</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>7b96170259a376ea79411c5713beb396</td><td colspan="2">archive containing fake Xeno installation</td></tr><tr><td>2ead73ed62f1c2beb9043ce92e774e0b</td><td colspan="2">malicious xeno.exe loader</td></tr><tr><td>0aadd62b535e683a5a2fe31fde546d07</td><td colspan="2">malicious xeno.exe loader</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/">Fake Roblox Hacks Target Discord and Gaming Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Takes Action to Strengthen NuGet Supply Chain Security</title>
		<link>https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/</link>
					<comments>https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 04:56:04 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[.net]]></category>
		<category><![CDATA[api keys]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[NuGet]]></category>
		<category><![CDATA[OIDC]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[supply chain security]]></category>
		<category><![CDATA[Trusted Publishing]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12120</guid>

					<description><![CDATA[<p>Microsoft has announced important security updates for NuGet.org aimed at improving software supply chain security and reducing the</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/">Microsoft Takes Action to Strengthen NuGet Supply Chain Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft has announced important security updates for <strong>NuGet.org</strong> aimed at improving software supply chain security and reducing the risk of compromised developer credentials being used to distribute malicious .NET packages.</p>



<p>Under the new policy, <strong>API keys created on or after August 17, 2026, will have a maximum lifetime of 30 days</strong>. Developers will no longer be able to create API keys that remain valid for 365 days. In addition, <strong>all API keys generated before August 17, 2026, will automatically expire on November 1, 2026</strong>.</p>



<p>The move is part of Microsoft&#8217;s broader effort to strengthen package security and encourage developers to adopt more secure authentication methods.</p>



<h2 class="wp-block-heading">Why Is Microsoft Reducing API Key Lifetimes?</h2>



<p>NuGet API keys are used by developers to publish packages to NuGet.org. These keys often function like passwords and are commonly stored in CI/CD pipelines, build servers, repository secrets, deployment environments, and other automation platforms.</p>



<p>Although this makes automated package publishing easier, it also creates an attractive target for cybercriminals. If attackers gain access to a long-lived API key, they could publish malicious packages under the name of a trusted project without immediately being detected.</p>



<p>By limiting API keys to just 30 days, Microsoft aims to significantly reduce the period during which a stolen credential can be exploited.</p>



<h2 class="wp-block-heading">The Growing Risk of Supply Chain Attacks</h2>



<p>Software supply chain attacks continue to rise as attackers increasingly target trusted software repositories instead of individual users.</p>



<p>Rather than directly attacking organizations, threat actors compromise developer credentials or package publishing accounts to insert malicious code into legitimate software packages. Once published, these compromised packages may be downloaded by thousands of developers and organizations, allowing malware to spread rapidly across multiple environments.</p>



<p>Microsoft explained that reducing the lifespan of publishing credentials is an important step toward minimizing this risk.</p>



<h2 class="wp-block-heading">Recent Incidents Highlight the Threat</h2>



<p>Microsoft referenced recent software package compromise incidents that demonstrate the dangers of stolen publishing credentials.</p>



<p>One notable example involved the <strong>NX Console</strong> package in the npm ecosystem. Attackers reportedly obtained valid publishing credentials and used them to release a malicious version of the package.</p>



<p>The compromised package was activated approximately <strong>6,000 times within just 36 minutes</strong> before it was removed. This incident showed how quickly attackers can exploit trusted software repositories when publishing credentials fall into the wrong hands.</p>



<p>Events like these continue to reinforce the need for stronger authentication and shorter-lived credentials across software ecosystems.</p>



<h2 class="wp-block-heading">Shorter API Keys Improve Security—but Don&#8217;t Eliminate the Risk</h2>



<p>While reducing API key validity lowers the window of opportunity for attackers, Microsoft emphasized that shorter expiration periods alone cannot completely prevent credential theft.</p>



<p>API keys can still be exposed through several common scenarios, including:</p>



<ul class="wp-block-list">
<li>Source code repositories</li>



<li>CI/CD pipeline logs</li>



<li>Insecure secret storage</li>



<li>Build servers</li>



<li>Compromised developer workstations</li>



<li>Accidentally shared configuration files</li>
</ul>



<p>If an attacker obtains an active API key, they may still be able to publish malicious packages before the credential expires.</p>



<p>For this reason, Microsoft is encouraging developers to move beyond traditional API keys altogether.</p>



<h2 class="wp-block-heading">Microsoft Recommends NuGet Trusted Publishing</h2>



<p>To provide a more secure publishing process, Microsoft recommends using <strong>NuGet Trusted Publishing</strong>, which became available in September 2025.</p>



<p>Trusted Publishing replaces long-lived API keys with <strong>OpenID Connect (OIDC)</strong> authentication, allowing CI/CD platforms to securely verify their identity without permanently storing publishing credentials.</p>



<p>Instead of relying on reusable secrets, supported CI/CD services generate a temporary identity token during the publishing workflow.</p>



<p>NuGet.org validates this token against security policies configured by the package owner before issuing a temporary publishing credential that is valid only for that specific publishing operation.</p>



<p>This approach greatly reduces the chances of stolen credentials being reused by attackers.</p>



<h2 class="wp-block-heading">How Trusted Publishing Works</h2>



<p>The Trusted Publishing workflow is designed to eliminate long-lived secrets from automated publishing environments.</p>



<p>The process works as follows:</p>



<ol class="wp-block-list">
<li>A supported CI/CD platform generates a short-lived OIDC identity token.</li>



<li>NuGet.org verifies the identity of the workflow.</li>



<li>Repository, workflow, and optional environment details are validated against the package owner&#8217;s security policy.</li>



<li>NuGet.org issues a temporary API key for that publishing session.</li>



<li>Once the publishing job is complete, the temporary credential expires automatically.</li>
</ol>



<p>Because no reusable API key is stored in repositories or CI/CD secrets, attackers have far fewer opportunities to steal publishing credentials.</p>



<h2 class="wp-block-heading">Benefits of Trusted Publishing</h2>



<p>Microsoft highlighted several advantages of adopting Trusted Publishing:</p>



<ul class="wp-block-list">
<li>Eliminates long-lived API keys.</li>



<li>Reduces the risk of credential theft.</li>



<li>Removes the need to store publishing secrets in repositories.</li>



<li>Simplifies credential rotation.</li>



<li>Improves software supply chain security.</li>



<li>Limits the impact of compromised developer environments.</li>



<li>Strengthens automated package publishing workflows.</li>
</ul>



<p>GitHub Actions and GitLab users are encouraged to migrate to Trusted Publishing before the August 2026 deadline.</p>



<h2 class="wp-block-heading">What Developers Should Do Before the Deadline</h2>



<p>Organizations that continue using traditional NuGet API keys should begin preparing now.</p>



<p>Microsoft recommends the following actions:</p>



<ul class="wp-block-list">
<li>Review all NuGet publishing workflows.</li>



<li>Identify API keys created before August 17, 2026.</li>



<li>Update automation to support 30-day API key rotation.</li>



<li>Restrict API keys to the minimum required package scope.</li>



<li>Apply the least-privilege principle for publishing permissions.</li>



<li>Avoid storing API keys in source code, configuration files, or logs.</li>



<li>Immediately revoke any API key that may have been exposed.</li>



<li>Begin migrating CI/CD pipelines to Trusted Publishing wherever possible.</li>
</ul>



<p>Taking these steps can help reduce the risk of malicious package publishing while ensuring a smooth transition to the new policy.</p>



<h2 class="wp-block-heading">Looking Ahead</h2>



<p>Microsoft indicated that shortening API key lifetimes is only one phase of its long-term software supply chain security strategy. As support for Trusted Publishing expands across additional CI/CD platforms, the company may further reduce API key validity periods in the future.</p>



<p>Developers and organizations are encouraged to adopt modern authentication methods such as OpenID Connect to strengthen package security, reduce reliance on reusable secrets, and better protect the software supply chain against evolving cyber threats.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/">Microsoft Takes Action to Strengthen NuGet Supply Chain Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New AtlasRAT Attack Uses 4-Stage In-Memory Loader to Target WeChat</title>
		<link>https://firsthackersnews.com/atlasrat-malware-in-memory-attack/</link>
					<comments>https://firsthackersnews.com/atlasrat-malware-in-memory-attack/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 03:41:55 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[AtlasRAT]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DLL Injection]]></category>
		<category><![CDATA[In-Memory Attack]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[remote access trojan]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[WeChat]]></category>
		<category><![CDATA[windows security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12099</guid>

					<description><![CDATA[<p>Security researchers have uncovered AtlasRAT, a sophisticated modular remote access trojan (RAT) that targets Windows systems using a</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/atlasrat-malware-in-memory-attack/">New AtlasRAT Attack Uses 4-Stage In-Memory Loader to Target WeChat</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have uncovered <strong>AtlasRAT</strong>, a sophisticated modular remote access trojan (RAT) that targets Windows systems using a <strong>four-stage in-memory attack chain</strong>. Instead of relying on files stored on disk, the malware loads its components directly into memory, making it significantly harder for traditional antivirus solutions to detect.</p>



<p>The malware also abuses <strong>WeChat</strong> by injecting malicious DLLs into the application, allowing attackers to maintain long-term access, monitor activity, and potentially steal sensitive information.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>AtlasRAT begins with a <strong>Delphi executable</strong> disguised as a legitimate <strong>AGE Flash Player installer (FlashPlay.exe)</strong>. While it appears harmless, the installer secretly launches the malware&#8217;s multi-stage infection process.</p>



<p>The attack unfolds in four stages:</p>



<ul class="wp-block-list">
<li><strong>Stage 1:</strong> Decrypts and loads the next payload directly into memory without creating files on disk.</li>



<li><strong>Stage 2:</strong> Rebuilds encrypted shellcode using multiple encryption techniques, including Base64, XOR, and AES-256-CBC.</li>



<li><strong>Stage 3:</strong> Connects to a hardcoded command-and-control (C2) server and manually loads the next component into memory.</li>



<li><strong>Stage 4:</strong> Executes <strong>MainDll.dll</strong>, the primary AtlasRAT payload that provides attackers with remote access to the infected system.</li>
</ul>



<p>By keeping every stage in memory, AtlasRAT significantly reduces forensic evidence and avoids many file-based security controls.</p>



<h2 class="wp-block-heading"><strong>Advanced Remote Access Capabilities</strong></h2>



<p>Once active, AtlasRAT establishes an encrypted communication channel using <strong>TLS</strong> combined with <strong>ChaCha20 encryption</strong>. The malware even uses a self-signed certificate that mimics Microsoft to help disguise its network traffic.</p>



<p>The RAT allows attackers to:</p>



<ul class="wp-block-list">
<li>Execute additional plugins remotely</li>



<li>Download and run malicious files</li>



<li>View and terminate running processes</li>



<li>Perform offline keylogging</li>



<li>Continue collecting data even when the system is disconnected from the internet</li>
</ul>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<h2 class="wp-block-heading"><strong>WeChat DLL Injection</strong></h2>



<p>One of AtlasRAT&#8217;s most notable capabilities is its ability to inject malicious DLLs into <strong>WeChat.exe</strong> using <strong>LoadLibraryW</strong> and <strong>CreateRemoteThread</strong>.</p>



<p>This enables attackers to:</p>



<ul class="wp-block-list">
<li>Hide inside a trusted application</li>



<li>Maintain long-term persistence</li>



<li>Monitor user activity</li>



<li>Potentially steal sensitive communications</li>
</ul>



<p>Using a legitimate messaging application also helps the malware blend into normal system activity.</p>



<h2 class="wp-block-heading"><strong>Persistence Techniques</strong></h2>



<p>AtlasRAT includes a dedicated persistence module called <strong>persistence86.dll</strong>, which helps the malware survive system reboots.</p>



<p>Its persistence techniques include:</p>



<ul class="wp-block-list">
<li>Modifying the Windows <strong>BITS</strong> database</li>



<li>Abusing <strong>NTUSER.MAN</strong> for logon persistence</li>



<li>Bypassing User Account Control (UAC)</li>



<li>Using registry hijacking to maintain access</li>
</ul>



<p>These methods make removal more difficult and help attackers retain control of compromised devices.</p>



<h2 class="wp-block-heading"><strong>Threat Intelligence Findings</strong></h2>



<p>Researchers identified <strong>146 unique AtlasRAT samples</strong> during a 180-day VirusTotal analysis. Multiple malware variants, versioned builds, and development artifacts suggest AtlasRAT is part of a continuously evolving malware framework rather than a single campaign.</p>



<p>Current public analysis has been shared by security researchers from <strong>ASEC</strong>, <strong>Proofpoint</strong>, <strong>Hexastrike</strong>, and other threat intelligence teams.</p>



<p>Proofpoint attributes AtlasRAT activity to <strong>TA4922</strong>, a Chinese-speaking cybercrime group known for using HR and finance-themed phishing lures. Other researchers have observed similarities with campaigns linked to the <strong>Silver Fox</strong> threat cluster, although there is currently no conclusive evidence connecting the two groups.</p>



<h2 class="wp-block-heading"><strong>Detection Opportunities</strong></h2>



<p>Security teams should monitor for indicators such as:</p>



<ul class="wp-block-list">
<li>Unusual TLS connections using suspicious self-signed Microsoft-themed certificates</li>



<li>Remote DLL injection into <strong>WeChat.exe</strong></li>



<li><strong>CreateRemoteThread</strong> activity originating from untrusted processes</li>



<li>Unexpected modifications to the <strong>BITS</strong> database or <strong>NTUSER.MAN</strong></li>



<li>Suspicious files such as <strong>offline.ini</strong>, <strong>AtlasPro.ini</strong>, <strong>MODIf.html</strong>, and <strong>Wxfun.dll</strong></li>
</ul>



<p>These behaviors may indicate an active AtlasRAT compromise.</p>



<p>AtlasRAT is more than a traditional remote access trojan. Its <strong>modular architecture</strong>, <strong>four-stage in-memory execution</strong>, <strong>encrypted communications</strong>, <strong>DLL injection</strong>, and <strong>advanced persistence mechanisms</strong> make it a highly capable threat designed to evade conventional security defenses.</p>



<p>As the malware continues to evolve, organizations should strengthen endpoint monitoring, memory-based threat detection, and behavioral analytics to identify attacks that bypass traditional file-based security solutions.</p>



<h2 class="wp-block-heading" id="h-iocs"><strong>IOCs</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Type</th></tr></thead><tbody><tr><td class="has-text-align-left" data-align="left">FlashPlay.exe</td><td class="has-text-align-left" data-align="left">File (executable)</td></tr><tr><td class="has-text-align-left" data-align="left">MainDll.dll</td><td class="has-text-align-left" data-align="left">File (DLL)</td></tr><tr><td class="has-text-align-left" data-align="left">Persistence86.dll</td><td class="has-text-align-left" data-align="left">File (DLL)</td></tr><tr><td class="has-text-align-left" data-align="left">C:\Users\xxx857857\Desktop\atlasPro验证版2026.6.2\Release\Plugin\x86\MainDll.pdb</td><td class="has-text-align-left" data-align="left">File (PDB path)</td></tr><tr><td class="has-text-align-left" data-align="left">C:\Users\xxx857857\Desktop\atlasPro Trial Version 2026.6.2\Release\Extend\x86\persistence86.pdb</td><td class="has-text-align-left" data-align="left">File (PDB path)</td></tr><tr><td class="has-text-align-left" data-align="left">150.158.50.175:443</td><td class="has-text-align-left" data-align="left">Network (IP:Port)</td></tr><tr><td class="has-text-align-left" data-align="left">116.204.169.70</td><td class="has-text-align-left" data-align="left">Network (IP)</td></tr><tr><td class="has-text-align-left" data-align="left">bifa668.com</td><td class="has-text-align-left" data-align="left">Network (Domain)</td></tr><tr><td class="has-text-align-left" data-align="left">23.226.57.50</td><td class="has-text-align-left" data-align="left">Network (IP)</td></tr><tr><td class="has-text-align-left" data-align="left">27.124.20.172</td><td class="has-text-align-left" data-align="left">Network (IP)</td></tr><tr><td class="has-text-align-left" data-align="left">38.46.13.82</td><td class="has-text-align-left" data-align="left">Network (IP)</td></tr><tr><td class="has-text-align-left" data-align="left">82.23.246.175</td><td class="has-text-align-left" data-align="left">Network (IP)</td></tr><tr><td class="has-text-align-left" data-align="left">192.163.162.30</td><td class="has-text-align-left" data-align="left">Network (IP)</td></tr><tr><td class="has-text-align-left" data-align="left">206.119.191.242</td><td class="has-text-align-left" data-align="left">Network (IP)</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/atlasrat-malware-in-memory-attack/">New AtlasRAT Attack Uses 4-Stage In-Memory Loader to Target WeChat</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/atlasrat-malware-in-memory-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NeedleStealer Targets Crypto Wallets and Browsers</title>
		<link>https://firsthackersnews.com/needlestealer-crypto-wallet-browser-theft/</link>
					<comments>https://firsthackersnews.com/needlestealer-crypto-wallet-browser-theft/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 03:50:08 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[CastleLoader]]></category>
		<category><![CDATA[Crypto Wallets]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Information Stealer]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[NeedleStealer]]></category>
		<category><![CDATA[security news]]></category>
		<category><![CDATA[Session hijacking]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12082</guid>

					<description><![CDATA[<p>Cybersecurity researchers have discovered new CastleLoader malware campaigns that now deliver NeedleStealer, a malware family designed to steal</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/needlestealer-crypto-wallet-browser-theft/">NeedleStealer Targets Crypto Wallets and Browsers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Cybersecurity researchers have discovered new <strong>CastleLoader</strong> malware campaigns that now deliver <strong>NeedleStealer</strong>, a malware family designed to steal cryptocurrency wallet recovery phrases, browser sessions, and user credentials. The latest activity shows that attackers are expanding their capabilities with more advanced tools and new programming languages, making these campaigns increasingly difficult to detect.</p>



<h2 class="wp-block-heading"><strong>CastleLoader Continues to Evolve</strong></h2>



<p>CastleLoader has been active for some time as a malware loader that delivers additional malicious payloads onto compromised systems. Previous campaigns primarily distributed information stealers and remote access tools. However, recent investigations reveal that threat actors have significantly upgraded the framework by integrating NeedleStealer into their attack chain.</p>



<p>Researchers also observed the first use of <strong>Rust</strong> and <strong>Golang</strong> within these campaigns. Combined with in-memory execution, these technologies help attackers avoid traditional security detection while improving the malware&#8217;s flexibility.</p>



<h2 class="wp-block-heading"><strong>NeedleStealer Focuses on Financial Theft</strong></h2>



<p>One of the most concerning additions is a Rust-based component that impersonates popular cryptocurrency wallet applications. Victims are presented with convincing recovery phrase prompts that appear legitimate. If users enter their wallet seed phrase, attackers can gain complete access to their cryptocurrency holdings.</p>



<p>Another component, developed in Golang, installs malicious browser extensions that appear to be legitimate software. These extensions allow attackers to hijack browser sessions and steal credentials without requiring victims to repeatedly enter their passwords.</p>



<h2 class="wp-block-heading"><strong>Multiple Campaigns Using Similar Techniques</strong></h2>



<p>Researchers identified three related campaigns—<strong>Urutyka, Garrigin, and Noidret</strong>—that all rely on CastleLoader as the initial infection method. Although each campaign introduces slight variations, they follow a similar multi-stage approach to deliver malware while making forensic analysis more difficult.</p>



<p>The attackers also continue to use digitally signed installers and carefully managed command-and-control infrastructure, increasing the likelihood that the malware will bypass security defenses.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>The latest CastleLoader campaigns demonstrate a clear shift toward targeting high-value financial information and online accounts. Instead of simply stealing passwords, attackers are now attempting to compromise cryptocurrency wallets and active browser sessions, allowing them to bypass authentication and gain access to valuable assets.</p>



<p>Organizations should remain alert for suspicious PowerShell activity, unexpected browser extensions, unusual outbound network connections, and software installers from untrusted sources. Behavioral monitoring and modern endpoint protection can also help detect malware that executes directly in memory.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>The integration of NeedleStealer marks another step in the evolution of CastleLoader. By combining multi-stage malware delivery, Rust and Golang payloads, browser session hijacking, and cryptocurrency theft, threat actors are building more sophisticated attack campaigns. As these techniques continue to evolve, organizations should strengthen endpoint security, monitor suspicious activity, and educate users about the risks of downloading software from unverified sources.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/needlestealer-crypto-wallet-browser-theft/">NeedleStealer Targets Crypto Wallets and Browsers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/needlestealer-crypto-wallet-browser-theft/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical RefluXFS Flaw Threatens Linux Systems</title>
		<link>https://firsthackersnews.com/refluxfs-linux-vulnerability/</link>
					<comments>https://firsthackersnews.com/refluxfs-linux-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 21:18:24 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Linux Malware]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12062</guid>

					<description><![CDATA[<p>A newly discovered Linux vulnerability, called RefluXFS (CVE-2026-64600), could allow a local user to gain root access by</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/refluxfs-linux-vulnerability/">Critical RefluXFS Flaw Threatens Linux Systems</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly discovered Linux vulnerability, called <strong>RefluXFS (CVE-2026-64600)</strong>, could allow a local user to gain <strong>root access</strong> by exploiting a flaw in the Linux kernel&#8217;s XFS filesystem. Security researchers at <strong>Qualys Threat Research Unit (TRU)</strong> discovered the issue and warned that it can be exploited even when <strong>SELinux is running in Enforcing mode</strong>.</p>



<p>The vulnerability affects the <strong>copy-on-write (CoW)</strong> feature of XFS. It is caused by a race condition that occurs when two <strong>O_DIRECT</strong> write operations access the same reflink-enabled file at nearly the same time.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>Normally, when a shared file is modified, XFS creates a new private copy of the data before writing changes. However, during this process, the kernel briefly releases an internal lock while waiting for transaction log space.</p>



<p>If another write request arrives during this short window, it can change the file mapping before the first operation finishes. As a result, the first write uses outdated information and writes data directly to the original disk block instead of a new one.</p>



<p>Since <strong>O_DIRECT</strong> bypasses the page cache, the corrupted data is written straight to disk, allowing attackers to overwrite protected system files.</p>



<h2 class="wp-block-heading"><strong>Why It Is Dangerous</strong></h2>



<p>Qualys demonstrated that a normal local user could exploit the flaw on a default <strong>RHEL 10.2</strong> system and remove the root account&#8217;s password protection within seconds. After the attack, the system granted <strong>passwordless root access</strong>.</p>



<p>The attack is difficult to detect because:</p>



<ul class="wp-block-list">
<li>No kernel log entries are generated.</li>



<li>The changes remain after a reboot.</li>



<li>Even systems protected by SELinux are vulnerable.</li>



<li>Existing Linux security protections do not block the attack.</li>
</ul>



<p>Researchers believe the vulnerability has existed since <strong>Linux kernel version 4.11</strong>, released in <strong>2017</strong>, potentially affecting <strong>more than 16 million systems</strong> worldwide.</p>



<h2 class="wp-block-heading"><strong>Who Is Affected?</strong></h2>



<p>A system is vulnerable if it has:</p>



<ul class="wp-block-list">
<li>Linux kernel <strong>4.11 or later</strong> without the security patch.</li>



<li>An <strong>XFS filesystem</strong> with <strong>reflink=1</strong> enabled.</li>



<li>A directory writable by an unprivileged user.</li>



<li>A valuable target file such as a <strong>SUID binary</strong> or protected system file.</li>
</ul>



<h3 class="wp-block-heading">Confirmed affected distributions include:</h3>



<ul class="wp-block-list">
<li>RHEL 8, 9 and 10</li>



<li>CentOS Stream 8, 9 and 10</li>



<li>Oracle Linux 8, 9 and 10</li>



<li>Rocky Linux 8, 9 and 10</li>



<li>AlmaLinux 8, 9 and 10</li>



<li>CloudLinux 8, 9 and 10</li>



<li>Amazon Linux 2 and Amazon Linux 2023</li>



<li>Fedora Server 31 and later</li>
</ul>



<h3 class="wp-block-heading">Lower-risk distributions</h3>



<ul class="wp-block-list">
<li>Debian</li>



<li>Ubuntu</li>



<li>SUSE</li>
</ul>



<p>These distributions are mainly affected only if <strong>XFS with reflink support</strong> has been manually configured.</p>



<h2 class="wp-block-heading"><strong>Existing Security Features Cannot Stop It</strong></h2>



<p>One of the biggest concerns is that common Linux security protections do not prevent this attack. Technologies such as <strong>SELinux</strong>, <strong>KASLR</strong>, <strong>SMEP</strong>, <strong>SMAP</strong>, kernel lockdown, and container isolation operate at different layers and cannot stop exploitation of this filesystem flaw.</p>



<p>At present, <strong>there is no temporary workaround</strong> that completely mitigates the vulnerability. Installing the security update is the only effective solution.</p>



<h2 class="wp-block-heading"><strong>AI Helped Discover the Flaw</strong></h2>



<p>The vulnerability was identified through a collaboration between <strong>Qualys</strong> and <strong>Anthropic</strong>. Researchers used Anthropic&#8217;s <strong>Claude Mythos Preview</strong> AI model to search for race-condition vulnerabilities similar to the well-known <strong>Dirty COW</strong> bug.</p>



<p>After identifying the issue, Qualys engineers independently verified the findings, created a proof-of-concept, and responsibly disclosed the vulnerability to Linux maintainers.</p>



<h2 class="wp-block-heading"><strong>Part of a Growing Trend</strong></h2>



<p>RefluXFS is one of several major Linux privilege escalation vulnerabilities disclosed during 2026. Other recent discoveries include:</p>



<ul class="wp-block-list">
<li><strong>Copy Fail (CVE-2026-31431)</strong></li>



<li><strong>Dirty Frag (CVE-2026-43284 and CVE-2026-43500)</strong></li>



<li><strong>DirtyClone (CVE-2026-43503)</strong></li>
</ul>



<p>These vulnerabilities highlight a growing trend of attackers exploiting flaws that allow protected files or memory to be modified, ultimately leading to privilege escalation.</p>



<h2 class="wp-block-heading"><strong>What Organizations Should Do</strong></h2>



<p>Organizations should patch affected systems as soon as possible, especially <strong>internet-facing servers</strong>, <strong>multi-tenant environments</strong>, and <strong>shared systems</strong>.</p>



<p>Security updates are already available for major enterprise Linux distributions, including <strong>RHEL, Oracle Linux, AlmaLinux, Rocky Linux, and Fedora</strong>. After installing the update, administrators should perform a <strong>full system reboot</strong> to ensure the patched kernel is running.</p>



<p>Since there is currently <strong>no reliable mitigation</strong> other than patching, keeping systems updated is the best defense against the RefluXFS vulnerability.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/refluxfs-linux-vulnerability/">Critical RefluXFS Flaw Threatens Linux Systems</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/refluxfs-linux-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>RabbitMQ OAuth Bug Allows Unauthorized Access</title>
		<link>https://firsthackersnews.com/rabbitmq-oauth-flaw/</link>
					<comments>https://firsthackersnews.com/rabbitmq-oauth-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 14:31:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[access control]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[CVE-2026-57219]]></category>
		<category><![CDATA[CVE-2026-57221]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Message Broker]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[OAuth Vulnerability]]></category>
		<category><![CDATA[rabbitmq]]></category>
		<category><![CDATA[RabbitMQ Security]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12015</guid>

					<description><![CDATA[<p>Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the popular open-source message broker used by organizations worldwide.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/rabbitmq-oauth-flaw/">RabbitMQ OAuth Bug Allows Unauthorized Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have disclosed <strong>two access-control vulnerabilities</strong> in <strong>RabbitMQ</strong>, the popular open-source message broker used by organizations worldwide. If exploited, these flaws could allow attackers to gain administrative control of a RabbitMQ server or access sensitive information about queues and users.</p>



<p>The vulnerabilities were discovered by <strong>Miggo Security</strong> and affect RabbitMQ versions starting from <strong>3.13.0</strong>. Security updates are now available, and organizations are encouraged to patch affected systems as soon as possible.</p>



<h3 class="wp-block-heading">Two Critical Security Flaws</h3>



<p>The first and more severe vulnerability, <strong>CVE-2026-57219</strong>, exposes RabbitMQ&#8217;s OAuth configuration through a management API endpoint that does not require authentication. If an organization stores an OAuth client secret for identity providers such as <strong>Auth0, Microsoft Entra ID, Keycloak, or UAA</strong>, an attacker with network access to the management interface could retrieve that secret.</p>



<p>Using the exposed credentials, an attacker may obtain administrator-level access to the RabbitMQ server, allowing them to manage messages, queues, users, and broker settings.</p>



<p>The second vulnerability, <strong>CVE-2026-57221</strong>, affects permission validation within RabbitMQ. Although less severe, it allows authenticated users with limited privileges to discover queues, exchanges, and usage statistics that they should not normally be able to access. In shared or multi-tenant environments, this information could help attackers gather intelligence for future attacks.</p>



<h3 class="wp-block-heading">Recommended Security Measures</h3>



<p>Both vulnerabilities have been fixed in <strong>RabbitMQ 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15</strong>.</p>



<p>Organizations should take the following steps to protect their RabbitMQ deployments:</p>



<ul class="wp-block-list">
<li>Update RabbitMQ to a supported patched version immediately.</li>



<li>Rotate OAuth client secrets after applying updates.</li>



<li>Restrict access to the RabbitMQ management interface (port <strong>15672</strong>) and avoid exposing it to public networks.</li>



<li>Isolate tenants using separate virtual hosts instead of shared environments.</li>



<li>Review container images and Helm charts to ensure they are not using vulnerable RabbitMQ versions.</li>



<li>Monitor RabbitMQ systems for unusual administrative activity or unauthorized access attempts.</li>
</ul>



<p>These vulnerabilities highlight the importance of securing management interfaces and regularly updating infrastructure components. Prompt patching, strong access controls, and continuous security monitoring remain essential for protecting messaging platforms and the applications that depend on them.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/rabbitmq-oauth-flaw/">RabbitMQ OAuth Bug Allows Unauthorized Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/rabbitmq-oauth-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Android VPN Apps Expose User Traffic</title>
		<link>https://firsthackersnews.com/android-vpn-apps-security-risks/</link>
					<comments>https://firsthackersnews.com/android-vpn-apps-security-risks/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 21:26:02 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[Android VPN Apps]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Traffic Leaks]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[VPN Security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12011</guid>

					<description><![CDATA[<p>Virtual Private Networks (VPNs) are widely used to protect online privacy, encrypt internet traffic, and secure users on</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-vpn-apps-security-risks/">Android VPN Apps Expose User Traffic</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Virtual Private Networks (VPNs) are widely used to protect online privacy, encrypt internet traffic, and secure users on public networks. However, a recent security analysis has revealed that <strong>281 Android VPN applications</strong> may expose users to serious privacy and security risks instead of protecting them.</p>



<p>Researchers identified multiple issues, including <strong>traffic leaks, third-party tracking, weak encryption practices, and VPN tunnel hijacking</strong>, raising concerns about the security of many Android VPN services.</p>



<h2 class="wp-block-heading"><strong>Security Risks Behind Insecure VPN Apps</strong></h2>



<p>The primary purpose of a VPN is to route all internet traffic through an encrypted tunnel, preventing unauthorized parties from monitoring user activity. However, researchers found that many Android VPN apps fail to protect all network traffic.</p>



<p>In some cases, <strong>DNS requests, IPv6 connections, and certain application traffic</strong> bypass the encrypted VPN tunnel, exposing information such as browsing activity, IP addresses, and other network metadata. These leaks are particularly concerning when users connect to public Wi-Fi networks, where attackers may monitor or manipulate exposed traffic.</p>



<p>The research also found that several VPN applications contain <strong>advertising, analytics, and tracking software development kits (SDKs)</strong>. These components can collect device identifiers, approximate location data, application usage statistics, and other telemetry. While some data collection may support diagnostics or performance monitoring, excessive tracking contradicts the privacy expectations users typically associate with VPN services.</p>



<p>Another concern is <strong>VPN tunnel hijacking</strong>, where malicious Android applications may exploit weaknesses in a VPN app&#8217;s implementation to misuse its network connection or interfere with its operation. Although Android has introduced security improvements over recent releases, poorly implemented VPN applications can still expose users to unnecessary risks.</p>



<h2 class="wp-block-heading"><strong>Recommendations for Android Users</strong></h2>



<p>Users should carefully evaluate VPN applications before installing them and avoid assuming that every VPN service provides the same level of security.</p>



<p>To improve protection, consider the following best practices:</p>



<ul class="wp-block-list">
<li>Choose reputable VPN providers with transparent ownership and privacy policies.</li>



<li>Prefer providers that have completed independent security audits.</li>



<li>Select VPNs that offer DNS leak protection, IPv6 protection, and a reliable kill switch.</li>



<li>Review requested permissions before installing any VPN application.</li>



<li>Keep Android devices and VPN apps updated with the latest security patches.</li>



<li>Enable Android&#8217;s <strong>Always-on VPN</strong> and <strong>Block connections without VPN</strong> settings when available.</li>



<li>Avoid installing unknown or untrusted applications alongside VPN software, especially on devices used for work or sensitive activities.</li>
</ul>



<p>As VPN usage continues to grow, this research highlights the importance of choosing trusted providers rather than relying solely on marketing claims. A VPN can only protect user privacy if it is implemented securely, maintained properly, and supported by transparent data-handling practices. Regular updates, careful provider selection, and good security hygiene remain essential for safeguarding personal and organizational data.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-vpn-apps-security-risks/">Android VPN Apps Expose User Traffic</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/android-vpn-apps-security-risks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Veeam Backup Flaw Discovered</title>
		<link>https://firsthackersnews.com/veeam-backup-flaw/</link>
					<comments>https://firsthackersnews.com/veeam-backup-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 06 Jul 2026 17:10:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Backup Security]]></category>
		<category><![CDATA[BinaryFormatter]]></category>
		<category><![CDATA[CVE-2026-44963]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[deserialization]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Veeam]]></category>
		<category><![CDATA[Veeam Backup]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11978</guid>

					<description><![CDATA[<p>Security researchers have discovered a high-severity vulnerability in Veeam Backup &#38; Replication, tracked as CVE-2026-44963, that could allow</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/veeam-backup-flaw/">Critical Veeam Backup Flaw Discovered</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have discovered a high-severity vulnerability in <strong>Veeam Backup &amp; Replication</strong>, tracked as <strong>CVE-2026-44963</strong>, that could allow authenticated domain users to execute remote code on backup servers.</p>



<p>The flaw is caused by insecure <strong>BinaryFormatter deserialization</strong>, a long-known security risk in .NET applications. According to researchers, the issue continues a pattern of similar vulnerabilities affecting Veeam&#8217;s .NET Remoting components.</p>



<h2 class="wp-block-heading">How the Vulnerability Works</h2>



<p>Veeam Backup &amp; Replication is widely used by organizations to manage backup, disaster recovery, and replication across virtual, physical, and cloud environments.</p>



<p>The vulnerability affects the <strong>Veeam Backup Service</strong>, which exposes a .NET Remoting HTTP endpoint on <strong>TCP port 8000</strong>.</p>



<p>Instead of allowing only trusted object types, the service relies on a <strong>blacklist-based filtering mechanism</strong>. While known dangerous classes are blocked, any unlisted serializable class is still accepted, creating an opportunity for attackers to bypass the protection.</p>



<h2 class="wp-block-heading">Low-Privilege Users Can Exploit the Flaw</h2>



<p>Researchers found that the vulnerability can be exploited by any <strong>authenticated domain user</strong>.</p>



<p>The application only verifies whether a user belongs to the standard Windows <strong>User</strong> group, meaning administrative privileges are not required to reach the vulnerable component.</p>



<p>An attacker can abuse this weakness to execute malicious serialized objects and ultimately run arbitrary commands on the backup server.</p>



<h2 class="wp-block-heading">Exploitation Process</h2>



<p>The attack follows a sequence of interactions with the Veeam service before delivering the malicious payload.</p>



<p>During exploitation, the attacker:</p>



<ul class="wp-block-list">
<li>Creates a restore session.</li>



<li>Initializes the backup session.</li>



<li>Sends a malicious BinaryFormatter payload.</li>



<li>Triggers insecure deserialization.</li>



<li>Executes arbitrary commands on the server.</li>
</ul>



<p>Researchers demonstrated that the exploit abuses <strong>System.Data.DataSet</strong> deserialization to instantiate <strong>ObjectDataProvider</strong>, which can invoke <strong>Process.Start()</strong> and execute attacker-controlled commands.</p>



<p>Because the <strong>Veeam Backup Service</strong> typically runs with <strong>SYSTEM</strong> privileges, successful exploitation can result in full control of the backup server.</p>



<h2 class="wp-block-heading">Why This Vulnerability Exists</h2>



<p>The root cause is Veeam&#8217;s continued use of <strong>BinaryFormatter</strong>, a serialization technology that Microsoft has considered unsafe and deprecated since .NET 5.</p>



<p>Researchers explain that relying on blocklists is not a long-term solution because attackers can continue discovering new classes capable of bypassing the restrictions.</p>



<p>Previous vulnerabilities, including <strong>CVE-2024-40711</strong> and <strong>CVE-2025-23120</strong>, were based on the same underlying weakness.</p>



<h2 class="wp-block-heading">Patch and Mitigation</h2>



<p>Veeam addressed the issue in <strong>version 12.3.2.4854 (KB4696)</strong> by adding the newly discovered gadget class to its BinaryFormatter blacklist.</p>



<p>However, researchers note that the update does <strong>not</strong> remove BinaryFormatter or redesign the underlying deserialization process.</p>



<p>In contrast, <strong>Veeam Backup &amp; Replication 13.x</strong> removes the BinaryFormatter-based implementation entirely, eliminating this class of vulnerabilities.</p>



<h2 class="wp-block-heading">Security Recommendations</h2>



<p>Organizations using <strong>Veeam Backup &amp; Replication 12.x</strong> should take immediate action to reduce the risk of exploitation.</p>



<p>Recommended security measures include:</p>



<ul class="wp-block-list">
<li>Apply the latest Veeam security updates.</li>



<li>Restrict access to <strong>TCP port 8000</strong>.</li>



<li>Limit network exposure of backup servers.</li>



<li>Consider deploying backup servers in <strong>workgroup mode</strong> instead of domain-joined environments where appropriate.</li>



<li>Monitor backup servers for suspicious deserialization or remote execution activity.</li>
</ul>



<p>Because backup infrastructure is frequently targeted by ransomware groups, organizations should prioritize patching this vulnerability to prevent attackers from gaining control over critical backup systems.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/veeam-backup-flaw/">Critical Veeam Backup Flaw Discovered</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/veeam-backup-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
