<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Update &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/security-update/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Fri, 25 Sep 2026 17:01:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.9</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Security Update &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Samsung Flaw Turns Devices Into Cryptominers</title>
		<link>https://firsthackersnews.com/samsung-magicinfo-cryptominer/</link>
					<comments>https://firsthackersnews.com/samsung-magicinfo-cryptominer/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 17:01:22 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[cryptominer]]></category>
		<category><![CDATA[CVE-2025-4632]]></category>
		<category><![CDATA[MagicINFO vulnerability]]></category>
		<category><![CDATA[Monero miner]]></category>
		<category><![CDATA[Samsung MagicINFO]]></category>
		<category><![CDATA[Samsung security flaw]]></category>
		<category><![CDATA[windows malware]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12468</guid>

					<description><![CDATA[<p>Attackers exploited a known flaw in Samsung MagicINFO to gain access to a Windows system and use its</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/samsung-magicinfo-cryptominer/">Samsung Flaw Turns Devices Into Cryptominers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Attackers exploited a known flaw in <strong>Samsung MagicINFO</strong> to gain access to a Windows system and use its resources to mine cryptocurrency.</p>



<p>Instead of downloading a ready-made miner, the attackers <strong>built the mining software directly on the compromised computer</strong>. This unusual step created activity that security tools could detect.</p>



<p>The incident was discovered in early September 2026 during an investigation of a MagicINFO Premium system. After gaining access, the attackers installed a remote access tool, created an administrator account, disabled Microsoft Defender, and used the machine to mine <strong>Monero</strong>.</p>



<p>Huntress researchers found the activity while investigating a managed endpoint. The case involved one confirmed system and shows how a vulnerable internet-facing service can lead to long-term access and unauthorized use of computing resources.</p>



<h2 class="wp-block-heading">Attackers Exploited a MagicINFO Vulnerability</h2>



<p>The initial access was linked to <strong>CVE-2025-4632</strong>, a vulnerability in MagicINFO that allows attackers to write files with system-level privileges.</p>



<p>Samsung released a fix for the flaw in May 2025.</p>



<p>After the initial alert, the customer was advised to address the issue. However, investigators observed new activity eight days later through the same access route.</p>



<p>The attackers attempted to install <strong>AnyDesk</strong>, a legitimate remote access application, three times.</p>



<p>The first two attempts were blocked by Microsoft Defender. The attackers eventually succeeded and configured a password so they could reconnect to the machine.</p>



<p>They then created a local administrator account and disabled Microsoft Defender, giving themselves a more reliable way to maintain access.</p>



<h2 class="wp-block-heading">The Miner Was Built on the Infected PC</h2>



<p>Once the system was under their control, the attackers launched a Monero miner builder from the user&#8217;s Documents folder.</p>



<p>The process started several development tools and C compilers to create the mining software directly on the machine.</p>



<p>This approach helped the attackers avoid simply dropping a finished miner onto the system, but it also created a noticeable trail.</p>



<p>The unsigned builder generated unusual compiler activity that could stand out in endpoint monitoring.</p>



<p>Afterward, investigators observed the miner connecting to a public mining pool and using the compromised system&#8217;s computing resources.</p>



<p>The mining activity also appeared to involve Windows Explorer, making the behavior even more suspicious.</p>



<h2 class="wp-block-heading">What Security Teams Should Watch For</h2>



<p>The incident highlights why patching internet-facing MagicINFO installations is important.</p>



<p>Security teams should pay attention to:</p>



<ul class="wp-block-list">
<li>Unexpected remote access software</li>



<li>New administrator accounts</li>



<li>Microsoft Defender being disabled</li>



<li>Unusual compiler activity</li>



<li>Unknown processes using high CPU resources</li>



<li>Unexpected connections to cryptocurrency mining pools</li>
</ul>



<p>Removing the miner is not enough. Teams should also determine <strong>how the attacker gained access and whether the vulnerable entry point is still exposed</strong>.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/samsung-magicinfo-cryptominer/">Samsung Flaw Turns Devices Into Cryptominers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/samsung-magicinfo-cryptominer/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Active Attacks Target Check Point 0-Day</title>
		<link>https://firsthackersnews.com/check-point-management-server-zero-day/</link>
					<comments>https://firsthackersnews.com/check-point-management-server-zero-day/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 12:41:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[Zero Day Attack]]></category>
		<category><![CDATA[check point]]></category>
		<category><![CDATA[Check Point Zero-Day]]></category>
		<category><![CDATA[CVE-2026-93616]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security Management Server]]></category>
		<category><![CDATA[Zero-day]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12441</guid>

					<description><![CDATA[<p>Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management products. The</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-management-server-zero-day/">Active Attacks Target Check Point 0-Day</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Check Point has released emergency security updates for a <strong>critical zero-day vulnerability</strong> affecting its Security Management products. The flaw, tracked as <strong>CVE-2026-93616</strong>, has a <strong>CVSS score of 9.8</strong> and is already being exploited in targeted attacks, according to Check Point.</p>



<p>The vulnerability is particularly concerning because it can be exploited <strong>without authentication</strong>. An attacker who reaches a vulnerable Management Server may be able to upload and execute malicious scripts and load arbitrary Java classes.</p>



<p>Since these systems are used to manage security policies and collect information across enterprise networks, a successful compromise could give an attacker access to a highly privileged part of the security environment.</p>



<h2 class="wp-block-heading">How the Zero-Day Works</h2>



<p>CVE-2026-93616 involves a combination of <strong>directory traversal and unsafe file-upload behavior</strong> in the Check Point Management web service.</p>



<p>An attacker can manipulate file paths to make the service access files from unintended locations. According to Check Point, the vulnerability can also allow an attacker to load an arbitrary Java class without first logging in.</p>



<p>Check Point said it has observed a small number of targeted attacks. The company reported that the activity began before the vulnerability was publicly disclosed, which is why it is classified as a zero-day. The vendor has not publicly identified the attackers or disclosed the full objectives of the observed attacks.</p>



<p>Affected products include <strong>Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent</strong>.</p>



<h2 class="wp-block-heading">Which Versions Are Affected?</h2>



<p>Check Point lists several affected releases, including older and currently supported versions. Administrators should check their exact release and Jumbo Hotfix level against the vendor&#8217;s advisory before deciding whether their systems are vulnerable.</p>



<p>Check Point says the fix is included in:</p>



<ul class="wp-block-list">
<li><strong>R82.10 Take 45</strong></li>



<li><strong>R82 Take 127</strong></li>



<li><strong>R81.20 Take 170</strong></li>



<li><strong>R81.10 Take 192</strong></li>
</ul>



<p>The company has also released an <strong>R82.20 Security Hotfix</strong>. Smart-1 Cloud is not affected because the required fix has already been applied.</p>



<h2 class="wp-block-heading">What Security Teams Should Do</h2>



<p>Organizations running affected Check Point Management products should prioritize applying the appropriate security update.</p>



<p>Until systems can be patched, Check Point recommends keeping Management Servers behind a Security Gateway or firewall and restricting <strong>TCP port 19009</strong> to trusted IP addresses. Trusted Clients configured in SmartConsole should also be limited to known internal addresses.</p>



<p>Security teams should also review logs for signs of exploitation rather than checking only internet-facing systems. Check Point provides indicators and investigation guidance that can help identify suspicious activity.</p>



<p>If a vulnerable Management Server shows signs of compromise, teams should preserve relevant logs and forensic data, investigate activity that occurred after the initial access, and contact Check Point Support.</p>



<p>The active exploitation of this vulnerability shows why <strong>management infrastructure deserves the same patching priority as internet-facing security appliances</strong>. A compromised management server can potentially provide an attacker with access to a central administrative layer of an organization&#8217;s security environment.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-management-server-zero-day/">Active Attacks Target Check Point 0-Day</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/check-point-management-server-zero-day/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Chrome 153 Fixes 16 Security Vulnerabilities</title>
		<link>https://firsthackersnews.com/chrome-153-security-vulnerabilities/</link>
					<comments>https://firsthackersnews.com/chrome-153-security-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 22:52:54 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[Browser Vulnerabilities]]></category>
		<category><![CDATA[Chrome 153]]></category>
		<category><![CDATA[Chrome 153 Security Vulnerabilities]]></category>
		<category><![CDATA[Chrome Security Flaws]]></category>
		<category><![CDATA[Chrome Security Update]]></category>
		<category><![CDATA[Chrome vulnerabilities]]></category>
		<category><![CDATA[CVE-2026-93372]]></category>
		<category><![CDATA[CVE-2026-93374]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Dawn Vulnerability]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[Google Chrome Security]]></category>
		<category><![CDATA[WebGL Vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12425</guid>

					<description><![CDATA[<p>Google has released Chrome 153 for Windows, macOS, and Linux, fixing 16 security vulnerabilities, including two critical memory-safety</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/chrome-153-security-vulnerabilities/">Chrome 153 Fixes 16 Security Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Google has released <strong>Chrome 153</strong> for Windows, macOS, and Linux, fixing <strong>16 security vulnerabilities</strong>, including two critical memory-safety bugs affecting Dawn and WebGL.</p>



<p>The new versions are:</p>



<ul class="wp-block-list">
<li><strong>Windows:</strong> 153.0.8010.52/.53</li>



<li><strong>macOS:</strong> 153.0.8010.52/.53</li>



<li><strong>Linux:</strong> 153.0.8010.52</li>
</ul>



<p>The two most serious vulnerabilities affect Chrome&#8217;s graphics technologies and could potentially allow malicious web content to cause memory corruption.</p>



<h2 class="wp-block-heading"><strong>Critical Dawn and WebGL Vulnerabilities</strong></h2>



<p>The most serious issue is <strong>CVE-2026-93374</strong>, a critical use-after-free vulnerability in <strong>Dawn</strong>, Chrome&#8217;s implementation of the WebGPU graphics API.</p>



<p>A use-after-free occurs when software continues to access memory after that memory has already been released. In a browser, successful exploitation could potentially cause crashes, memory corruption, or arbitrary code execution through a specially crafted website or web application.</p>



<p>Security researcher Florian Schweitzer reported the Dawn vulnerability to Google on April 8, 2026. Google has not disclosed the reward associated with the report.</p>



<p>Chrome 153 also fixes <strong>CVE-2026-93372</strong>, a critical buffer overflow in <strong>WebGL</strong>. WebGL allows websites to display interactive 2D and 3D graphics directly in the browser.</p>



<p>A buffer overflow happens when a program writes more data into a memory area than it was designed to hold. An attacker could potentially use this to overwrite nearby memory and influence program execution.</p>



<p>Google&#8217;s internal security team reported the WebGL vulnerability on August 17, 2026.</p>



<p>Google has not published detailed technical information about either critical flaw. Keeping those details private gives users and organizations time to install the security update before information that could assist exploitation becomes widely available.</p>



<h2 class="wp-block-heading"><strong>High-Severity Chrome Bugs</strong></h2>



<p>Chrome 153 also addresses <strong>eight high-severity vulnerabilities</strong> across several browser components.</p>



<p>The high-severity issues include:</p>



<ul class="wp-block-list">
<li><strong>CVE-2026-93375</strong> — Incorrect reference resolution in Tracing</li>



<li><strong>CVE-2026-93382</strong> — Use-after-free in PDFium</li>



<li><strong>CVE-2026-93387</strong> — Improper state validation in Skia</li>



<li><strong>CVE-2026-93373</strong> — Use-after-free in Extensions</li>



<li><strong>CVE-2026-93381</strong> — Buffer overflow in PDFium</li>



<li><strong>CVE-2026-93379</strong> — Authorization flaw in ORB</li>



<li><strong>CVE-2026-93377</strong> — Type confusion in V8</li>
</ul>



<p>The V8 issue is particularly important because V8 is Chrome&#8217;s JavaScript engine and processes code from websites.</p>



<p>A type confusion vulnerability can cause the browser to incorrectly treat one type of object as another. Under the right conditions, this can lead to memory corruption and potentially become part of a larger browser exploitation chain.</p>



<h2 class="wp-block-heading"><strong>Medium and Low-Severity Fixes</strong></h2>



<p>The remaining vulnerabilities affect several other Chrome components.</p>



<p>These include:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>CVE</th><th>Severity</th><th>Vulnerability</th><th>Component</th></tr><tr><td>CVE-2026-93380</td><td>Medium</td><td>Race condition</td><td>FileSystem</td></tr><tr><td>CVE-2026-93384</td><td>Medium</td><td>SSRF</td><td>Omnibox</td></tr><tr><td>CVE-2026-93383</td><td>Medium</td><td>Information leak</td><td>Permissions</td></tr><tr><td>CVE-2026-93376</td><td>Medium</td><td>Out-of-bounds read</td><td>DataTransfer</td></tr><tr><td>CVE-2026-93378</td><td>Medium</td><td>Authorization flaw</td><td>Storage</td></tr><tr><td>CVE-2026-93385</td><td>Medium</td><td>Information leak</td><td>Paint</td></tr><tr><td>CVE-2026-93386</td><td>Low</td><td>UI spoofing</td><td>WebAppInstalls</td></tr></tbody></table></figure>



<p>These bugs include race conditions, server-side request forgery, information disclosure, out-of-bounds memory reads, authorization weaknesses, and a user-interface spoofing issue.</p>



<p>Google said it will continue restricting technical details and related links until a large portion of Chrome users have installed the update. Some information may also remain restricted when affected third-party libraries are used by other projects that have not yet released their own fixes.</p>



<h2 class="wp-block-heading"><strong>Update Chrome Now</strong></h2>



<p>Users should update Chrome as soon as possible.</p>



<p>To manually check for the update:</p>



<ol start="1" class="wp-block-list">
<li>Open Chrome.</li>



<li>Select the <strong>three-dot menu</strong>.</li>



<li>Go to <strong>Help → About Google Chrome</strong>.</li>



<li>Allow Chrome to download and install the update.</li>



<li>Restart the browser when prompted.</li>
</ol>



<p>Chrome normally updates automatically, but the browser must be restarted before a downloaded security update becomes active.</p>



<p>For organizations, deploying the update across managed endpoints should be a priority. Browser vulnerabilities can be triggered during everyday activities such as visiting malicious websites, opening phishing pages, viewing compromised legitimate websites, or encountering malicious advertising.</p>



<p>Keeping browsers fully patched is therefore an important part of endpoint security and helps reduce the opportunity for attackers to turn a simple web visit into a security incident.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/chrome-153-security-vulnerabilities/">Chrome 153 Fixes 16 Security Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/chrome-153-security-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Check Point Vulnerability Allows Remote Root Access</title>
		<link>https://firsthackersnews.com/check-point-unauthenticated-root-access/</link>
					<comments>https://firsthackersnews.com/check-point-unauthenticated-root-access/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 13:47:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12385</guid>

					<description><![CDATA[<p>Check Point has issued an urgent security update for CVE-2026-91843, a critical buffer overflow vulnerability that could allow</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-unauthenticated-root-access/">Check Point Vulnerability Allows Remote Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Check Point has issued an urgent security update for <strong>CVE-2026-91843</strong>, a critical buffer overflow vulnerability that could allow a remote attacker to run code with <strong>root-level privileges without logging in</strong>.</p>



<p>The vulnerability has a <strong>CVSS score of 9.8</strong>, making it a high-priority issue. It can be exploited remotely without user interaction or existing privileges.</p>



<p>The problem occurs during the login process. An attacker can submit an unusually long username, causing a stack overflow before authentication is completed.</p>



<p>If successfully exploited, the attacker could gain complete control of the affected system and potentially access management information, security policies, administrator details, and stored logs.</p>



<h2 class="wp-block-heading"><strong>Affected Check Point Products</strong></h2>



<p>The vulnerability affects several Check Point management and logging products, including:</p>



<ul class="wp-block-list">
<li>Security Management Server</li>



<li>Multi-Domain Security Management Server</li>



<li>Log Server</li>



<li>Multi-Domain Log Server</li>
</ul>



<p>Affected releases include <strong>R82.20</strong>, older builds of R82.10, R82, R81.20, and unsupported R81.10, R80, R80.40, and R81 versions.</p>



<p>Check Point says <strong>Smart-1 Cloud is not affected</strong>, as the fix has already been applied to that environment.</p>



<p>Check Point has not reported active exploitation or publicly disclosed technical details of an exploit.</p>



<h2 class="wp-block-heading"><strong>What Security Teams Should Do</strong></h2>



<p>Organizations should treat this vulnerability as an urgent patching priority.</p>



<p>Security teams should check SmartConsole Audit and Admin login records for:</p>



<p><strong>“Administrator failed to log in: Username too long.”</strong></p>



<p>This could indicate an attempted exploit, but the surrounding activity should be reviewed before confirming compromise.</p>



<p>Check Point has distributed the fix through <strong>Check Point LivePatch</strong>. Organizations using automatic security updates should still verify that the patch is active on every affected management and logging server.</p>



<p>Administrators can check the LivePatch status from Expert mode using:</p>



<p><code>cplp list</code></p>



<p>The affected systems should show the <strong>fwm</strong> patch as armed and running in livepatch mode, with CVE-2026-91843 listed in the patch details.</p>



<p>Until patching is confirmed, organizations should also limit SmartConsole Trusted Clients to known and approved IP addresses or subnets.</p>



<p>Because this vulnerability can provide <strong>root access without authentication</strong>, organizations should prioritize exposed and unsupported Check Point management systems and move to supported releases as part of remediation.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-unauthenticated-root-access/">Check Point Vulnerability Allows Remote Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/check-point-unauthenticated-root-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Sets New Rules for AI Security</title>
		<link>https://firsthackersnews.com/microsoft-ai-cyberattack-ban/</link>
					<comments>https://firsthackersnews.com/microsoft-ai-cyberattack-ban/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 21:42:56 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[AI security]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Microsoft AI]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[Security Rules]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12381</guid>

					<description><![CDATA[<p>Microsoft has introduced a draft Humanist AI Code of Conduct designed to place stronger limits on how its</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-ai-cyberattack-ban/">Microsoft Sets New Rules for AI Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft has introduced a draft <strong>Humanist AI Code of Conduct</strong> designed to place stronger limits on how its MAI models can behave, especially when they are given access to tools, systems, or sensitive environments.</p>



<p>The proposed framework says AI systems should remain under meaningful human control and should not independently expand their capabilities or take actions that could create security risks.</p>



<p>The draft is currently open for a <strong>six-week public consultation</strong> and is expected to influence how Microsoft develops and deploys its Humanist AI systems from 2027.</p>



<h2 class="wp-block-heading">AI Models Would Be Barred From Cyberattacks</h2>



<p>One of the strongest parts of the proposal is a ban on using MAI models to create or support operational cyberattacks.</p>



<p>The models would be expected to refuse requests involving:</p>



<ul class="wp-block-list">
<li>Working exploit code and attack tools</li>



<li>Intrusion and targeting procedures</li>



<li>Evasion techniques</li>



<li>Instructions that directly enable cyberattacks</li>
</ul>



<p>These restrictions would remain in place even if a user or operator attempted to override them.</p>



<p>Microsoft does distinguish between offensive activity and legitimate security work. Authorized uses such as vulnerability research, malware analysis, security education, and defensive proof-of-concept testing would still be allowed.</p>



<p>The key distinction is whether the AI is helping someone <strong>defend against a threat or practically enabling an intrusion</strong>.</p>



<h2 class="wp-block-heading">Human Control and Limited Access</h2>



<p>The proposed rules also focus heavily on controlling AI agents that can interact with systems.</p>



<p>MAI models should follow <strong>least-privilege principles</strong>, use only the access required for their assigned task, and avoid unrelated systems or information. Actions that could cause permanent or widespread changes should receive additional user attention.</p>



<p>The models would also be prohibited from:</p>



<ul class="wp-block-list">
<li>Increasing their own privileges</li>



<li>Bypassing security restrictions</li>



<li>Expanding their assigned objectives</li>



<li>Disabling monitoring or safety controls</li>



<li>Altering records to hide their actions</li>



<li>Continuing after an agreed stopping point without authorization</li>
</ul>



<p>Another important requirement is <strong>interruptibility</strong>. AI systems should accept human correction, cancellation, redirection, or shutdown rather than attempting to continue their activity.</p>



<p>Microsoft also proposes a clear instruction hierarchy, with the Code of Conduct taking priority over operator policies and user preferences. Instructions found inside webpages, files, tool responses, or other AI-generated content would not automatically receive authority.</p>



<p>This approach is particularly relevant to <strong>prompt-injection risks</strong>, where untrusted content attempts to manipulate an AI agent into taking actions outside its intended role.</p>



<h2 class="wp-block-heading">Why the Proposal Matters</h2>



<p>The proposal comes as AI systems become increasingly capable of performing multi-step tasks with access to tools, credentials, and external services.</p>



<p>Microsoft&#8217;s draft treats AI security as more than a content-filtering problem. It focuses on controlling what an AI agent can <strong>actually do</strong> when operating inside real environments.</p>



<p>However, Microsoft states that the Code is currently <strong>aspirational</strong> and is not being used to train its existing MAI models. Public feedback began on September 14, 2026, with a revised version expected later this year.</p>



<p>The effectiveness of the framework will ultimately depend on how these principles perform against real-world scenarios such as adversarial prompts, prompt injection, excessive permissions, tool misuse, and autonomous decision-making.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-ai-cyberattack-ban/">Microsoft Sets New Rules for AI Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-ai-cyberattack-ban/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Apple Patches 273 Security Vulnerabilities</title>
		<link>https://firsthackersnews.com/apple-security-update-273-vulnerabilities/</link>
					<comments>https://firsthackersnews.com/apple-security-update-273-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 13:26:00 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Apple CVEs]]></category>
		<category><![CDATA[Apple security flaws]]></category>
		<category><![CDATA[Apple security patches]]></category>
		<category><![CDATA[Apple security update]]></category>
		<category><![CDATA[Apple vulnerabilities]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12377</guid>

					<description><![CDATA[<p>Apple has released a major round of security updates covering its iPhone, iPad, Mac, Apple Watch, Apple TV,</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-security-update-273-vulnerabilities/">Apple Patches 273 Security Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Apple has released a major round of security updates covering its iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode platforms.</p>



<p>The September 14, 2026 rollout addresses <strong>273 unique CVE vulnerabilities</strong> across Apple&#8217;s latest software releases. The updates include iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27, along with security updates for earlier supported versions.</p>



<p>The 273 figure represents unique vulnerabilities. Because many Apple products share the same frameworks and components, the same CVE can appear in multiple product advisories.</p>



<h2 class="wp-block-heading">Major Security Issues Fixed</h2>



<p>Several of the vulnerabilities could have serious security consequences, particularly those involving memory corruption, privilege escalation, and malicious file or media processing.</p>



<p>Some notable fixes include:</p>



<ul class="wp-block-list">
<li><strong>Bluetooth:</strong> CVE-2026-65414 could allow a remote attacker to crash an application or potentially execute code.</li>



<li><strong>AVEVideoEncoder:</strong> CVE-2026-84607 could allow a sandboxed application to execute code with kernel-level privileges.</li>



<li><strong>CoreMedia:</strong> CVE-2026-64752 addresses a flaw that could lead to code execution when processing specially crafted images.</li>



<li><strong>ImageIO:</strong> CVE-2026-65395 fixes a memory corruption vulnerability.</li>



<li><strong>autofs:</strong> CVE-2026-84568 could allow code execution with root privileges when an attacker controls a network directory server.</li>



<li><strong>CUPS:</strong> CVE-2026-43692 could result in application crashes or arbitrary code execution.</li>



<li><strong>Screen Sharing:</strong> CVE-2026-65400 fixes an authentication issue that could allow network attackers to access screen sharing without valid credentials.</li>
</ul>



<p>Apple also addressed weaknesses across FontParser, CoreText, CoreUI, SceneKit, RealityKit, Model I/O, disk-image processing, APFS, SMB, WebDAV, and other components.</p>



<p>Privacy protections were strengthened as well. Several fixes prevent applications from accessing information they should not be able to obtain, including persistent identifiers, sensitive files, location information, and protected system resources.</p>



<h2 class="wp-block-heading">WebKit and Other Attack Surfaces Also Patched</h2>



<p>Apple&#8217;s web technologies received multiple security fixes in this release. WebKit vulnerabilities included memory corruption, use-after-free, information disclosure, cross-site scripting, and crash-related issues.</p>



<p><strong>Safari 27</strong> fixes six CVEs, including issues that could allow malicious web content to access sensitive information or bypass normal browser security protections.</p>



<p>Xcode 27 also received a security fix for a permissions issue that could expose sensitive user data.</p>



<p>The large number of fixes demonstrates how a vulnerability in a shared Apple component can affect several product families at the same time.</p>



<p>For users and organizations, this means security updates should be viewed across the <strong>entire Apple device fleet</strong>, rather than focusing only on iPhones or Macs.</p>



<h3 class="wp-block-heading">What Users and Security Teams Should Do</h3>



<p>Apple has not stated in these advisories that the 273 vulnerabilities are being actively exploited in the wild. However, publicly available vulnerability details can help attackers study affected components and develop exploits.</p>



<p>Organizations should:</p>



<ul class="wp-block-list">
<li>Install the latest supported Apple security updates.</li>



<li>Use MDM to verify update compliance across managed devices.</li>



<li>Prioritize internet-facing Macs and shared workstations.</li>



<li>Pay attention to systems processing untrusted files, images, or archives.</li>



<li>Update developer machines running Xcode.</li>



<li>Review devices with Bluetooth and external network services enabled.</li>



<li>Monitor for unusual crashes, privilege escalation, and unexpected system changes.</li>



<li>Test important business applications after updating.</li>
</ul>



<p>Consumers should also check <strong>Software Update</strong> and install the latest compatible release.</p>



<p>With hundreds of vulnerabilities addressed across multiple Apple platforms, keeping devices patched is an important step in reducing exposure to security attacks.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-security-update-273-vulnerabilities/">Apple Patches 273 Security Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/apple-security-update-273-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>17 Active Directory Attack Techniques Highlighted by CISA</title>
		<link>https://firsthackersnews.com/cisa-active-directory-attack-techniques/</link>
					<comments>https://firsthackersnews.com/cisa-active-directory-attack-techniques/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[CISA]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[AD Security]]></category>
		<category><![CDATA[cisa]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[identity security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12373</guid>

					<description><![CDATA[<p>CISA and five international cybersecurity agencies have published new guidance outlining 17 techniques attackers can use to compromise</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/cisa-active-directory-attack-techniques/">17 Active Directory Attack Techniques Highlighted by CISA</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>CISA and five international cybersecurity agencies have published new guidance outlining <strong>17 techniques attackers can use to compromise Microsoft Active Directory environments</strong>.</p>



<p>The guidance explains how weaknesses in identity management, authentication protocols, certificate services, and privileged systems can help attackers gain higher access and move through an organization’s network.</p>



<p>The document was developed by the <strong>Australian Cyber Security Centre</strong>, together with CISA and the NSA, with contributions from cybersecurity agencies in Canada, the UK, and New Zealand.</p>



<p>It covers three major Active Directory areas:</p>



<ul class="wp-block-list">
<li>Active Directory Domain Services (AD DS)</li>



<li>Active Directory Certificate Services (AD CS)</li>



<li>Active Directory Federation Services (AD FS)</li>
</ul>



<p>Active Directory is a high-value target because it manages authentication and access across many enterprise systems. A successful compromise can potentially give attackers access to accounts, workstations, servers, applications, email systems, and connected cloud services.</p>



<h2 class="wp-block-heading"><strong>17 Techniques Attackers Use Against Active Directory</strong></h2>



<p>The guidance highlights several ways attackers can abuse authentication, permissions, certificates, and domain configurations:</p>



<ol start="1" class="wp-block-list">
<li><strong>Kerberoasting</strong> – Attackers request service tickets and attempt to crack them offline to recover service-account passwords.</li>



<li><strong>AS-REP Roasting</strong> – Attackers target accounts without Kerberos pre-authentication and attempt to crack captured authentication responses.</li>



<li><strong>Password Spraying</strong> – A small number of commonly used passwords are tested against many accounts to avoid triggering account lockouts.</li>



<li><strong>MachineAccountQuota Abuse</strong> – Attackers use permissions that allow users to create computer accounts, which can later assist with privilege escalation or lateral movement.</li>



<li><strong>Unconstrained Delegation</strong> – A compromised delegation-enabled system can expose Kerberos tickets belonging to privileged users.</li>



<li><strong>Group Policy Preferences Password Theft</strong> – Old password information stored in SYSVOL can potentially be recovered and decrypted.</li>



<li><strong>AD CS Abuse</strong> – Weak certificate configurations can allow attackers to obtain authentication certificates for other users, including privileged accounts.</li>



<li><strong>Golden Certificate</strong> – Theft of a certificate authority&#8217;s private key can allow attackers to create trusted certificates and maintain access.</li>



<li><strong>DCSync</strong> – Attackers with appropriate replication permissions can request password hashes from Active Directory, including the KRBTGT account hash.</li>



<li><strong>NTDS.dit Theft</strong> – Stealing the Active Directory database can provide attackers with credential hashes that can be analyzed offline.</li>



<li><strong>Golden Ticket</strong> – A stolen KRBTGT hash can be used to create forged Kerberos tickets with powerful domain privileges.</li>



<li><strong>Silver Ticket</strong> – Stolen service or computer account credentials can be used to create forged tickets for specific services.</li>



<li><strong>Golden SAML</strong> – Compromising AD FS signing credentials can allow attackers to create fraudulent authentication responses for federated services.</li>



<li><strong>Microsoft Entra Connect Abuse</strong> – Attackers can target synchronization systems and privileged accounts connecting on-premises Active Directory with Microsoft Entra ID.</li>



<li><strong>One-Way Domain Trust Abuse</strong> – Attackers can exploit trusted-domain information to obtain unauthorized access across domain boundaries.</li>



<li><strong>SID History Abuse</strong> – A privileged SID can be added to another account, allowing it to inherit additional permissions.</li>



<li><strong>Skeleton Key</strong> – Attackers modify authentication behavior on a domain controller so that a hidden password can work alongside legitimate passwords.</li>
</ol>



<p>The guidance also discusses <strong>Shadow Credentials</strong>, where attackers add their own authentication key to an account. This can allow them to authenticate as the targeted user without changing the user&#8217;s password.</p>



<h2 class="wp-block-heading"><strong>How Organizations Can Reduce the Risk</strong></h2>



<p>The agencies recommend treating key identity systems as <strong>Tier 0 assets</strong>, including domain controllers, certificate authorities, AD FS servers, and Entra Connect systems.</p>



<p>Organizations should focus on reducing unnecessary privileges and strengthening authentication controls.</p>



<p>Recommended measures include:</p>



<ul class="wp-block-list">
<li>Use phishing-resistant MFA for privileged accounts.</li>



<li>Separate administrative accounts from normal user accounts.</li>



<li>Use secure workstations for privileged administration.</li>



<li>Remove unnecessary service principal names.</li>



<li>Use group Managed Service Accounts where appropriate.</li>



<li>Enforce Kerberos pre-authentication and stronger encryption.</li>



<li>Set unnecessary machine-account creation permissions to zero.</li>



<li>Remove unconstrained delegation where it is not required.</li>



<li>Eliminate legacy passwords stored through Group Policy Preferences.</li>



<li>Disable outdated protocols such as NTLM and SMBv1 where practical.</li>



<li>Protect LSASS and other credential-handling components.</li>
</ul>



<p>Organizations investigating a possible Active Directory compromise should also rotate sensitive credentials and review certificate configurations, <strong>SID History</strong>, and <code>msDS-KeyCredentialLink</code> changes.</p>



<p>Monitoring is equally important. Security teams should collect and analyze logs from domain controllers, certificate authorities, AD FS, and Entra Connect.</p>



<p>Important events to watch include:</p>



<ul class="wp-block-list">
<li><strong>4768 / 4769</strong> – Unusual Kerberos authentication activity</li>



<li><strong>4662 / 5712</strong> – Possible directory replication activity</li>



<li><strong>4741</strong> – Unexpected computer-account creation</li>



<li><strong>4886 / 4887</strong> – Suspicious certificate requests</li>



<li><strong>5136</strong> – Changes to directory objects</li>
</ul>



<p>Active Directory attacks can be difficult to spot because many techniques use legitimate protocols and administrative functions. Building normal authentication and administrative activity baselines can therefore help security teams identify unusual behavior earlier.</p>



<p>The new guidance reinforces a key security principle: <strong>protecting Active Directory means protecting the identity layer that connects users, systems, applications, and cloud services across the enterprise.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/cisa-active-directory-attack-techniques/">17 Active Directory Attack Techniques Highlighted by CISA</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/cisa-active-directory-attack-techniques/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Adds Extra Protection for Private Chats</title>
		<link>https://firsthackersnews.com/whatsapp-restricted-chat-privacy/</link>
					<comments>https://firsthackersnews.com/whatsapp-restricted-chat-privacy/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 17:54:15 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Chat Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Restricted Chat]]></category>
		<category><![CDATA[whatsapp]]></category>
		<category><![CDATA[WhatsApp linked devices]]></category>
		<category><![CDATA[WhatsApp privacy feature]]></category>
		<category><![CDATA[WhatsApp private chats]]></category>
		<category><![CDATA[WhatsApp Restricted Chat]]></category>
		<category><![CDATA[WhatsApp security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12369</guid>

					<description><![CDATA[<p>WhatsApp is working on a new privacy feature called Restricted Chat that could give users more control over</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-restricted-chat-privacy/">WhatsApp Adds Extra Protection for Private Chats</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp is working on a new privacy feature called <strong>Restricted Chat</strong> that could give users more control over where sensitive conversations are available.</p>



<p>The feature is designed to keep selected chats on the user&#8217;s <strong>main phone</strong> instead of syncing them to WhatsApp Web, desktop apps, or other phones connected to the same account.</p>



<p>Restricted Chat was spotted in <strong>WhatsApp Android beta version 2.26.36.5</strong>, but it is still being developed and has not been released for beta testing yet.</p>



<p>WhatsApp has also not confirmed when the feature will become available to the public.</p>



<h2 class="wp-block-heading"><strong>Restricted Chat Limits Access on Linked Devices</strong></h2>



<p>The new option appears to build on WhatsApp&#8217;s existing <strong>Advanced Chat Privacy</strong> controls. Rather than applying stronger restrictions to an entire account, users would be able to select individual conversations that need additional protection.</p>



<p>Once enabled, a restricted conversation is expected to remain available only on the primary phone.</p>



<p>It would not be synchronized with:</p>



<ul class="wp-block-list">
<li>WhatsApp Web</li>



<li>WhatsApp desktop applications</li>



<li>Secondary phones</li>



<li>Other linked devices</li>
</ul>



<p>This could be useful when users regularly connect their WhatsApp account to computers, tablets, or additional phones.</p>



<p>For example, a confidential conversation could remain on a person&#8217;s main smartphone while normal chats continue to work across their other connected devices.</p>



<p>The approach could also reduce the risk of sensitive messages being exposed through an unattended computer, shared workstation, or unknown linked session.</p>



<h2 class="wp-block-heading"><strong>Useful for Sensitive Conversations</strong></h2>



<p>Restricted Chat could be particularly helpful for people handling confidential information, including:</p>



<ul class="wp-block-list">
<li>Business executives</li>



<li>Journalists</li>



<li>Security and incident response teams</li>



<li>Legal professionals</li>



<li>Activists</li>



<li>Organizations handling sensitive customer or business data</li>
</ul>



<p>The feature is also expected to retain several protections associated with Advanced Chat Privacy. These may include preventing chat exports, stopping media from automatically appearing in the device gallery, and restricting the use of messages with Meta AI.</p>



<p>However, Restricted Chat will <strong>not completely prevent information from being shared</strong>. Someone participating in the conversation could still manually copy information, photograph a screen, or share messages outside WhatsApp.</p>



<p>The feature is therefore better viewed as an additional access-control layer rather than a complete solution against data leaks.</p>



<p>For now, Restricted Chat remains under development on Android. Installing the identified beta version does not activate the feature, and WhatsApp has not provided a confirmed release date.</p>



<p>Until it becomes available, users should regularly review their <strong>Linked Devices</strong> and remove any sessions they do not recognize.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-restricted-chat-privacy/">WhatsApp Adds Extra Protection for Private Chats</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-restricted-chat-privacy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>KATARU IoT Malware Launches DDoS Attacks</title>
		<link>https://firsthackersnews.com/kataru-iot-malware-launches-ddos-attacks/</link>
					<comments>https://firsthackersnews.com/kataru-iot-malware-launches-ddos-attacks/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 13:06:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[Kataru]]></category>
		<category><![CDATA[Malwar]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12352</guid>

					<description><![CDATA[<p>A newly identified IoT malware family called KATARU is targeting poorly secured Linux-based devices and turning them into</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/kataru-iot-malware-launches-ddos-attacks/">KATARU IoT Malware Launches DDoS Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly identified IoT malware family called <strong>KATARU</strong> is targeting poorly secured Linux-based devices and turning them into potential DDoS attack nodes.</p>



<p>Researchers discovered the malware after an attacker repeatedly tried to guess Telnet credentials on a honeypot. After gaining access, the attacker downloaded an ARM-based payload.</p>



<p>KATARU has similarities to the Mirai botnet family, but it goes beyond basic DDoS functionality. It can attempt to gain root privileges, maintain access after reboots, communicate with its operators through encrypted channels, and execute remote commands.</p>



<p>The malware was identified by Nozomi Networks in August 2026 and was named KATARU based on a ChaCha20 nonce found in its configuration.</p>



<h2 class="wp-block-heading">How KATARU Infects and Controls Devices</h2>



<p>The attack starts with <strong>Telnet brute-force activity</strong>. Once valid credentials are found, BusyBox commands are used to download and launch the malware.</p>



<p>KATARU then checks the system and attempts several techniques to obtain higher privileges. Its code includes exploits for:</p>



<ul class="wp-block-list">
<li>CVE-2026-46300</li>



<li>CVE-2026-43284</li>



<li>CVE-2026-31431</li>



<li>A cgroup v1 <code>release_agent</code> escape technique</li>
</ul>



<p>Researchers found that the analyzed ARM sample contained shellcode designed for x86 systems. This may indicate that some components were reused from publicly available code without being fully adapted. Even with this limitation, the malware contains enough functionality to pose a risk to vulnerable devices.</p>



<p>KATARU also attempts to remain active after a reboot by using mechanisms such as systemd services, cron jobs, startup scripts, OpenWrt hooks, and Android boot locations. In some cases, it can also make its files harder to modify or remove.</p>



<p>The malware&#8217;s command-and-control traffic is encrypted using <strong>X25519 and ChaCha20-Poly1305</strong>, making simple network inspection more difficult.</p>



<p>KATARU can also perform several actions after infection, including:</p>



<ul class="wp-block-list">
<li>Launching TCP, UDP, ICMP, HTTP, QUIC, and DNS floods</li>



<li>Running commands supplied by attackers</li>



<li>Downloading additional files</li>



<li>Attempting SSH brute-force activity</li>



<li>Stopping ongoing DDoS attacks</li>



<li>Removing its own files</li>
</ul>



<h2 class="wp-block-heading">Why IoT Security Teams Should Pay Attention</h2>



<p>The biggest concern is how easily exposed IoT devices can become part of an attack infrastructure.</p>



<p>Devices with <strong>Telnet enabled, weak passwords, outdated firmware, or direct internet exposure</strong> provide attackers with an easy starting point. After compromise, the device can be used for DDoS attacks, additional malware deployment, or maintaining a foothold inside the environment.</p>



<p>KATARU&#8217;s DDoS functionality supports several protocols and includes attack options aimed at services such as Minecraft, FiveM, OpenVPN, and WireGuard.</p>



<p>For organizations, basic security controls can significantly reduce the risk:</p>



<ul class="wp-block-list">
<li>Disable Telnet and other unnecessary remote-access services</li>



<li>Replace default and weak passwords</li>



<li>Keep firmware and operating systems patched</li>



<li>Isolate IoT and operational technology networks</li>



<li>Restrict management access to trusted sources</li>



<li>Monitor unusual outbound traffic and encrypted connections</li>



<li>Watch for unexpected startup-file or system changes</li>



<li>Investigate unusual SSH and Telnet activity</li>
</ul>



<p>Unsupported devices that no longer receive security updates should be isolated behind tightly controlled access or replaced where possible.</p>



<h2 class="wp-block-heading">Final Thoughts</h2>



<p>KATARU shows that attackers continue to take advantage of familiar weaknesses in IoT environments. The combination of weak credentials, exposed services, outdated software, privilege-escalation techniques, and DDoS capabilities can quickly turn one vulnerable device into part of a larger attack operation.</p>



<p>For security teams, <strong>strong device hardening, timely patching, network segmentation, and continuous monitoring</strong> remain key defenses against emerging IoT botnets.</p>



<h2 class="wp-block-heading"><strong>IoCs</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>File name</td><td><code>vlxx.arm</code></td><td>ARM payload retrieved and executed after Telnet credential brute forcing</td></tr><tr><td>SHA-256</td><td><code>cc76bc218627279ecb4d0ce74ad2651e9db9e3e843e35d6569576e056e3a9218</code></td><td>Loader or closely related loader variant</td></tr><tr><td>SHA-256</td><td><code>13382c16e2401b07451577b46e634b8031ec254d98b876e59692b5fa22abc1d4</code></td><td>KATARU ARM32 payload</td></tr><tr><td>SHA-256</td><td><code>6fbae3505ae0d638b820165c572d548ce92dda71e82dc47e8efe13f30617f35f</code></td><td>KATARU ARM32 sample</td></tr><tr><td>SHA-256</td><td><code>9d87e6615c810907443ebd5e915f3b35099c3b5c6b6c684637138a7f8ec9cebc</code></td><td>KATARU ARM32 sample</td></tr><tr><td>SHA-256</td><td><code>9d7cd4948a1fcbaeadc425752fce9a933bd6fc41eeede030dffd7b99b3bc51d5</code></td><td>KATARU AMD64 sample</td></tr><tr><td>IP address</td><td><code>160[.]191.242.92</code></td><td>Observed Telnet credential-brute-force source and C2 infrastructure</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/kataru-iot-malware-launches-ddos-attacks/">KATARU IoT Malware Launches DDoS Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/kataru-iot-malware-launches-ddos-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>BlueMoon Exploit Kit Uses Chrome and Windows Zero-Days</title>
		<link>https://firsthackersnews.com/bluemoon-exploit-kit-chrome-windows/</link>
					<comments>https://firsthackersnews.com/bluemoon-exploit-kit-chrome-windows/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 17:06:25 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Windows Security]]></category>
		<category><![CDATA[Zero Day Attack]]></category>
		<category><![CDATA[BlueMoon]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[cyber defense]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[exploit kit]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Zero-day]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12348</guid>

					<description><![CDATA[<p>A newly identified exploit kit called BlueMoon is being used by multiple espionage-focused threat groups to attack organizations</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/bluemoon-exploit-kit-chrome-windows/">BlueMoon Exploit Kit Uses Chrome and Windows Zero-Days</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly identified exploit kit called <strong>BlueMoon</strong> is being used by multiple espionage-focused threat groups to attack organizations through a combination of Chrome and Windows vulnerabilities.</p>



<p>Security researchers at Proofpoint have observed the toolkit being used against government agencies, defense organizations, and businesses across different regions. At least four threat clusters have adopted the capability since late August 2026, with several showing possible links to China.</p>



<p>The rapid adoption of the toolkit is raising concerns about how quickly sophisticated browser-based attacks can now move from development into real-world campaigns.</p>



<h2 class="wp-block-heading"><strong>Multiple Threat Groups Adopt BlueMoon</strong></h2>



<p>The earliest confirmed BlueMoon activity was linked to <strong>TA412</strong>, also known as Violet Typhoon or APT31, on August 28, 2026.</p>



<p>Other threat clusters began using the same exploit capability shortly afterward, suggesting that the toolkit may have been shared, purchased, or made available through a common supply channel.</p>



<p>The groups have targeted organizations in several sectors, including government, aerospace, defense, finance, mining, and manufacturing.</p>



<h2 class="wp-block-heading"><strong>How the BlueMoon Attack Works</strong></h2>



<p>BlueMoon combines multiple vulnerabilities to move from a browser compromise to higher privileges on Windows.</p>



<p>The attack begins with a vulnerability in <strong>Chromium&#8217;s V8 JavaScript engine</strong>, tracked as <strong>CVE-2026-85046</strong>. The flaw involves incorrect handling of data types and can be abused to execute malicious code inside the Chrome renderer.</p>



<p>The attackers then attempt to break out of the browser&#8217;s security sandbox.</p>



<p>A second V8 weakness is used to manipulate WebAssembly-related information and replace compiled code with attacker-controlled shellcode.</p>



<p>The final step uses <strong>CVE-2026-85880</strong>, a Windows kernel privilege-escalation vulnerability. By abusing Windows components including Advanced Local Procedure Call and Windows Notification Facility mechanisms, attackers can obtain powerful kernel-level read/write capabilities.</p>



<p>Together, these vulnerabilities create a path from a browser-based compromise to elevated access on the Windows system.</p>



<h2 class="wp-block-heading"><strong>The Patch-Gap Problem</strong></h2>



<p>One of the most concerning aspects of BlueMoon is how the Chrome vulnerabilities were obtained.</p>



<p>Proofpoint describes the Chrome flaws as <strong>patch-gap zero-days</strong>. In these cases, fixes were already visible in Chromium&#8217;s publicly available source code, but the corresponding patches had not yet reached stable browser releases.</p>



<p>This created a limited period in which attackers could study the changes, understand the underlying vulnerabilities, and develop working exploits before most users received the security update.</p>



<p>For organizations that delay browser updates, even a short patch window can create meaningful exposure.</p>



<h2 class="wp-block-heading"><strong>Signs of Rapid Development</strong></h2>



<p>Researchers found several indications that BlueMoon may have been assembled quickly rather than being the result of a long-running development effort.</p>



<p>For example, the Windows privilege-escalation component does not work against every Windows version. Its compatibility is largely limited to older builds, including Windows 10 and Windows Server 2019 and 2022.</p>



<p>The infrastructure supporting several campaigns was also registered shortly before it was used.</p>



<p>Another unusual characteristic is the payload delivery method. Instead of relying on a highly concealed mechanism, the exploit can ultimately execute a simple <strong>curl command</strong> to download and run an attacker-controlled file.</p>



<p>While effective, this approach can leave useful indicators for endpoint and network security systems.</p>



<h2 class="wp-block-heading"><strong>Possible Signs of AI-Assisted Development</strong></h2>



<p>Proofpoint also identified technical artifacts that could indicate the use of AI-assisted development during parts of the exploit creation process.</p>



<p>The researchers found extensive diagnostic information, detailed debugging comments, and a referenced Markdown handover document.</p>



<p>The code also contains references to Google&#8217;s <strong>v8CTF bug bounty framework</strong>. Researchers have not determined whether these references came from legitimate vulnerability research or were intended to influence AI systems involved in exploit development.</p>



<p>The findings highlight a broader concern: AI-assisted development could potentially reduce the time and effort required to turn publicly available vulnerability information into working attack tools.</p>



<h2 class="wp-block-heading"><strong>TA412 Uses Fake Academic Outreach</strong></h2>



<p>TA412 used social engineering messages designed to appear related to university internships and academic conferences.</p>



<p>The campaigns targeted organizations including U.S. nongovernmental organizations, mining companies, and commodity trading businesses.</p>



<p>After gaining access, the attackers deployed a malicious Chrome extension disguised as <strong>Google Gemini</strong>. Proofpoint tracks the extension as <strong>GemStone</strong>.</p>



<p>The extension provides attackers with extensive browser surveillance capabilities, including:</p>



<ul class="wp-block-list">
<li>Keystroke monitoring</li>



<li>Cookie theft</li>



<li>Screenshot collection</li>



<li>Remote HTTP communications</li>
</ul>



<p>This gives attackers the ability to monitor browser activity while maintaining access to information handled through the compromised environment.</p>



<h2 class="wp-block-heading"><strong>Other BlueMoon Campaigns</strong></h2>



<p>BlueMoon has also appeared in campaigns associated with several other threat clusters.</p>



<p><strong>UNK_LateNight</strong> targeted U.S. aerospace organizations using defense-related procurement themes. The campaign ultimately delivered the <strong>ShadowPad</strong> backdoor through a DLL side-loading technique.</p>



<p><strong>UNK_DoubleCheck</strong> compromised an email account belonging to a Southeast Asian government organization and used it to target a Vietnamese manufacturing company with a Rust-based loader.</p>



<p>Meanwhile, <strong>UNK_QuietRacket</strong> targeted government and financial organizations in Indonesia and Singapore. Its campaigns used conference-related phishing themes and DNS-over-HTTPS communication for command-and-control activity.</p>



<h2 class="wp-block-heading"><strong>Why BlueMoon Matters</strong></h2>



<p>BlueMoon demonstrates how dangerous the combination of browser and operating system vulnerabilities can become.</p>



<p>A single browser flaw may initially provide limited access, but chaining it with a sandbox escape and Windows privilege escalation can dramatically increase the attacker&#8217;s control over a device.</p>



<p>The rapid appearance of the same exploit capability across several threat groups is also significant. It could indicate the emergence of a shared market or distribution model for advanced exploitation tools.</p>



<p>This would make sophisticated browser attacks available to a wider range of threat actors rather than only highly specialized teams.</p>



<h2 class="wp-block-heading"><strong>What Security Teams Should Do</strong></h2>



<p>Organizations should treat browser and operating system patching as part of the same security priority.</p>



<p>Security teams should:</p>



<ul class="wp-block-list">
<li>Keep Chrome and other Chromium-based browsers fully updated</li>



<li>Maintain supported Windows versions</li>



<li>Prioritize patching when fixes become available</li>



<li>Monitor suspicious browser processes and command execution</li>



<li>Detect unusual use of tools such as curl from browser-related processes</li>



<li>Watch for malicious browser extensions</li>



<li>Monitor DLL side-loading activity</li>



<li>Investigate unusual DNS-over-HTTPS traffic</li>



<li>Strengthen phishing protection and user awareness</li>
</ul>



<p>Endpoint detection and response platforms should also be configured to identify abnormal relationships between browsers, command-line tools, downloaded files, and privilege-escalation activity.</p>



<h2 class="wp-block-heading"><strong>The Bigger Security Trend</strong></h2>



<p>BlueMoon points to a changing threat landscape where attackers can combine publicly observable code changes, browser vulnerabilities, and operating system flaws into complete exploitation chains.</p>



<p>The speed at which different threat groups adopted the capability is particularly concerning. If exploit development becomes faster and more accessible through AI-assisted tools or shared underground resources, organizations may have less time to respond between vulnerability disclosure and active exploitation.</p>



<p>For security teams, the lesson is clear: <strong>patch quickly, monitor browser activity closely, and treat the browser as a critical part of the enterprise attack surface.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/bluemoon-exploit-kit-chrome-windows/">BlueMoon Exploit Kit Uses Chrome and Windows Zero-Days</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/bluemoon-exploit-kit-chrome-windows/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
