<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Update &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/security-update/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Fri, 17 Jul 2026 05:17:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Security Update &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Critical Flaw Found in Shark Robot Vacuums</title>
		<link>https://firsthackersnews.com/shark-robot-vacuum-vulnerability/</link>
					<comments>https://firsthackersnews.com/shark-robot-vacuum-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 17 Jul 2026 05:17:21 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[AWS IoT]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[home network security]]></category>
		<category><![CDATA[IoT Security]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[Shark Robot Vacuum]]></category>
		<category><![CDATA[Smart Home Security]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12039</guid>

					<description><![CDATA[<p>A newly disclosed security vulnerability could put millions of internet-connected Shark robot vacuums at risk. According to security</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/shark-robot-vacuum-vulnerability/">Critical Flaw Found in Shark Robot Vacuums</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly disclosed security vulnerability could put <strong>millions of internet-connected Shark robot vacuums</strong> at risk. According to security researchers, the flaw could allow attackers to remotely execute commands, access sensitive device data, and potentially take control of affected vacuums.</p>



<p>The vulnerability is linked to insecure cloud permissions and a built-in command execution feature found in certain Shark vacuum firmware. At the time of disclosure, no official patch had been released.</p>



<h2 class="wp-block-heading">How the Vulnerability Works</h2>



<p>Researchers found that the issue affects internet-connected Shark robot vacuums that communicate through AWS IoT services. By exploiting weak cloud permissions, an attacker who gains access to one vulnerable device could potentially interact with other Shark vacuums connected to the same cloud environment.</p>



<p>The most serious concern is a command execution feature that allows specially crafted messages to run commands on the device. During testing, researchers successfully demonstrated that credentials taken from one Shark vacuum could be used to execute commands on another compatible device.</p>



<p>Some Shark models also include cameras and store household maps for navigation. Researchers warned that a successful attack could allow unauthorized access to:</p>



<ul class="wp-block-list">
<li>Live camera feeds on supported models</li>



<li>Home mapping data</li>



<li>Stored Wi-Fi credentials</li>



<li>Remote control of the vacuum</li>



<li>Device information and telemetry</li>
</ul>



<p>The research also identified a large number of active Shark devices communicating with the affected cloud infrastructure, indicating that the potential impact could be significant.</p>



<h2 class="wp-block-heading">Recommended Security Measures</h2>



<p>Until an official fix is released, Shark robot vacuum owners should take steps to reduce their exposure.</p>



<p>Recommended actions include:</p>



<ul class="wp-block-list">
<li>Keep the vacuum firmware updated with the latest available version.</li>



<li>Monitor SharkNinja for future security updates and advisories.</li>



<li>Place smart home and IoT devices on a separate Wi-Fi network whenever possible.</li>



<li>Regularly review your home network for unknown or suspicious devices.</li>



<li>Remove unused smart devices from your network.</li>



<li>Change your Wi-Fi password if you suspect unauthorized access.</li>
</ul>



<p>This vulnerability highlights the growing importance of securing Internet of Things (IoT) devices. As more connected devices become part of everyday life, regular updates, network segmentation, and strong security practices remain essential for protecting home networks and personal data.</p>



<p></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/shark-robot-vacuum-vulnerability/">Critical Flaw Found in Shark Robot Vacuums</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/shark-robot-vacuum-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NuGet Packages Deliver Pepesoft Malware</title>
		<link>https://firsthackersnews.com/malicious-nuget-packages-2/</link>
					<comments>https://firsthackersnews.com/malicious-nuget-packages-2/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 20:04:06 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[.net]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Developer Security]]></category>
		<category><![CDATA[NuGet]]></category>
		<category><![CDATA[Pepesoft Malware]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[software supply chain]]></category>
		<category><![CDATA[supply chain attack]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[windows security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12033</guid>

					<description><![CDATA[<p>Security researchers have identified 11 malicious NuGet packages disguised as game cheats, automation bots, and management tools. Instead</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/malicious-nuget-packages-2/">NuGet Packages Deliver Pepesoft Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have identified <strong>11 malicious NuGet packages</strong> disguised as game cheats, automation bots, and management tools. Instead of providing the advertised functionality, these packages install a Windows malware known as <strong>Pepesoft</strong>.</p>



<p>The malicious packages were distributed as <strong>.NET command-line tools</strong>, allowing users to install them using the standard <code>dotnet tool install</code> command. They primarily targeted players of popular games such as <strong>Albion Online, GTA5RP, GrandRP, Majestic RP, Lineage 2, Russian Fishing 4,</strong> and <strong>Throne and Liberty</strong>.</p>



<p>After discovering the campaign, researchers reported the packages to NuGet&#8217;s security team for removal.</p>



<h2 class="wp-block-heading"><strong>How the Malware Operates</strong></h2>



<p>Once installed, the malicious package downloads a second-stage payload called <strong>pepesoft.exe</strong> from attacker-controlled infrastructure hosted on <strong>GitHub Releases</strong> and <strong>Hugging Face</strong>.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="559" src="https://firsthackersnews.com/wp-content/uploads/2026/07/image-1-1024x559.png" alt="" class="wp-image-12034" srcset="https://firsthackersnews.com/wp-content/uploads/2026/07/image-1-300x164.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/07/image-1-768x419.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/07/image-1-1024x559.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/07/image-1-1536x838.png 1536w, https://firsthackersnews.com/wp-content/uploads/2026/07/image-1.png 1600w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><strong>Malicious NuGet Package Attack Flow (Source: Socket)</strong></figcaption></figure>



<p>The malware includes several techniques to avoid detection and maintain its operation. It uses <strong>Google DNS-over-HTTPS</strong> to resolve download servers, making it more difficult for traditional DNS-based security controls to block its activity. In many cases, it also attempts to synchronize the system clock before downloading additional components.</p>



<p>After installation, Pepesoft contacts remote servers to retrieve configuration updates and collect information from the infected device. The malware generates a unique hardware identifier and gathers system information such as usernames, computer names, hardware details, network information, public IP addresses, and approximate location.</p>



<p>Some variants also include <strong>Telegram bot functionality</strong>, allowing attackers to remotely capture screenshots of the victim&#8217;s desktop. These screenshots could expose browser sessions, password managers, cryptocurrency wallets, authentication prompts, private conversations, or other sensitive information displayed on the screen.</p>



<h2 class="wp-block-heading"><strong>Security Recommendations</strong></h2>



<p>Developers and organizations should review their development environments for suspicious NuGet packages and investigate any unexpected execution of <strong>pepesoft.exe</strong>.</p>



<p>Recommended security measures include:</p>



<ul class="wp-block-list">
<li>Review installed NuGet packages and remove any unknown or suspicious tools.</li>



<li>Verify the authenticity of open-source packages before installation.</li>



<li>Monitor systems for unexpected execution of <strong>pepesoft.exe</strong>.</li>



<li>Watch for unusual outbound connections to GitHub, Hugging Face, and other unknown infrastructure.</li>



<li>Monitor for unexpected DNS-over-HTTPS traffic from development systems.</li>



<li>Keep endpoint security solutions updated and regularly scan developer workstations.</li>



<li>Educate developers about software supply chain attacks and package verification.</li>
</ul>



<p>This campaign highlights the growing risk of <strong>software supply chain attacks</strong>, where attackers disguise malicious packages as legitimate developer tools. Carefully verifying third-party packages before installation remains one of the most effective ways to reduce this risk.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/malicious-nuget-packages-2/">NuGet Packages Deliver Pepesoft Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/malicious-nuget-packages-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Debian 13.6 Brings Major Security Fixes</title>
		<link>https://firsthackersnews.com/debian-13-6-security-updates/</link>
					<comments>https://firsthackersnews.com/debian-13-6-security-updates/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 21:43:50 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[Curl]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[Debian 13.6]]></category>
		<category><![CDATA[fwupd]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Linux security]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[QEMU]]></category>
		<category><![CDATA[Security updates]]></category>
		<category><![CDATA[system update]]></category>
		<category><![CDATA[UEFI Secure Boot]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12020</guid>

					<description><![CDATA[<p>The Debian Project has released Debian 13.6, the latest update for the stable Debian 13 &#8220;Trixie&#8221; release. Published</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/debian-13-6-security-updates/">Debian 13.6 Brings Major Security Fixes</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The <strong>Debian Project</strong> has released <strong>Debian 13.6</strong>, the latest update for the stable <strong>Debian 13 &#8220;Trixie&#8221;</strong> release. Published on <strong>July 11, 2026</strong>, this update includes important <strong>security patches, bug fixes, and updated installation images</strong>.</p>



<p>This is a maintenance release rather than a new version of Debian. Existing users can upgrade their systems using the standard APT update process without performing a full operating system upgrade.</p>



<h2 class="wp-block-heading"><strong>What&#8217;s New in Debian 13.6?</strong></h2>



<p>Debian 13.6 combines previously released security updates into a single package, making it easier for users to keep their systems up to date.</p>



<p>The release also includes:</p>



<ul class="wp-block-list">
<li>An updated Linux kernel (6.12.94+deb13)</li>



<li>Improved installation media for new deployments</li>



<li>Security fixes for Apache HTTP Server</li>



<li>Curl updates that address credential leaks and other security issues</li>



<li>QEMU updates with multiple security improvements</li>



<li>Bug fixes across various Debian packages</li>
</ul>



<p>The update also improves <strong>UEFI Secure Boot</strong> support by updating <strong>fwupd</strong> to version <strong>2.0.20</strong>. Debian recommends installing firmware updates provided by your hardware manufacturer before making changes to Secure Boot on supported systems.</p>



<h2 class="wp-block-heading"><strong>Security Recommendations</strong></h2>



<p>Administrators should update their systems as soon as possible to benefit from the latest security fixes.</p>



<p>Recommended actions include:</p>



<ul class="wp-block-list">
<li>Run <code>apt update &amp;&amp; apt upgrade</code> to install the latest updates.</li>



<li>Use the new Debian 13.6 installation images for fresh deployments.</li>



<li>Apply firmware updates recommended by your hardware vendor.</li>



<li>Update Apache, Curl, QEMU, and other affected packages.</li>



<li>If your organization relies on accurate IP geolocation, obtain the latest GeoLite database directly from its provider instead of using Debian&#8217;s bundled package.</li>
</ul>



<p>Keeping Debian systems updated is one of the most effective ways to reduce security risks and ensure stable, reliable operation.</p>



<h2 class="wp-block-heading"><strong>Notable CVEs Fixed</strong></h2>



<ul class="wp-block-list">
<li><strong>Apache2:</strong> CVE-2026-29167, CVE-2026-48913, CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42536, CVE-2026-42535, CVE-2026-44186, CVE-2026-49975, CVE-2026-43951, CVE-2026-44185, CVE-2026-44119, CVE-2026-44631</li>



<li><strong>Curl:</strong> CVE-2025-14524, CVE-2026-3783, CVE-2025-14819, CVE-2026-1965, CVE-2026-3784, CVE-2026-5545, CVE-2026-4873, CVE-2026-3805, CVE-2026-5773, CVE-2026-6253, CVE-2026-6429, CVE-2026-6276, CVE-2026-7168</li>



<li><strong>QEMU:</strong> CVE-2024-6519, CVE-2026-2243, CVE-2026-3195, CVE-2026-3196, CVE-2026-3842, CVE-2026-3886, CVE-2026-3890, CVE-2026-41435 through CVE-2026-41440, CVE-2026-5744, CVE-2026-5761, CVE-2026-5763, CVE-2026-6502, CVE-2026-8341, CVE-2026-48002 through CVE-2026-48004, CVE-2026-48914, CVE-2026-48915, CVE-2026-6425, CVE-2026-8343</li>



<li><strong>Linux kernel:</strong> Updated through multiple Debian security advisories, alongside refreshed signed AMD64 and ARM64 kernel packages.<a href="https://www.debian.org/releases/stable/errata" target="_blank" rel="noreferrer noopener">debian</a></li>



<li><strong>Other affected software:</strong> <code>dcmtk</code>, <code>dhcpcd</code>, <code>giflib</code>, <code>libxml2</code>, <code>mutt</code>, <code>python3.13</code>, <code>rsync</code>, <code>sshfs-fuse</code>, <code>xz-utils</code>, <code>wireshark</code>, <code>OpenSSL</code>, Chromium, Firefox ESR, Nginx, Redis, PostgreSQL 17, and Thunderbird received security-related updates.</li>
</ul>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/debian-13-6-security-updates/">Debian 13.6 Brings Major Security Fixes</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/debian-13-6-security-updates/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>RabbitMQ OAuth Bug Allows Unauthorized Access</title>
		<link>https://firsthackersnews.com/rabbitmq-oauth-flaw/</link>
					<comments>https://firsthackersnews.com/rabbitmq-oauth-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 14:31:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[access control]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[CVE-2026-57219]]></category>
		<category><![CDATA[CVE-2026-57221]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Message Broker]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[OAuth Vulnerability]]></category>
		<category><![CDATA[rabbitmq]]></category>
		<category><![CDATA[RabbitMQ Security]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12015</guid>

					<description><![CDATA[<p>Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the popular open-source message broker used by organizations worldwide.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/rabbitmq-oauth-flaw/">RabbitMQ OAuth Bug Allows Unauthorized Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have disclosed <strong>two access-control vulnerabilities</strong> in <strong>RabbitMQ</strong>, the popular open-source message broker used by organizations worldwide. If exploited, these flaws could allow attackers to gain administrative control of a RabbitMQ server or access sensitive information about queues and users.</p>



<p>The vulnerabilities were discovered by <strong>Miggo Security</strong> and affect RabbitMQ versions starting from <strong>3.13.0</strong>. Security updates are now available, and organizations are encouraged to patch affected systems as soon as possible.</p>



<h3 class="wp-block-heading">Two Critical Security Flaws</h3>



<p>The first and more severe vulnerability, <strong>CVE-2026-57219</strong>, exposes RabbitMQ&#8217;s OAuth configuration through a management API endpoint that does not require authentication. If an organization stores an OAuth client secret for identity providers such as <strong>Auth0, Microsoft Entra ID, Keycloak, or UAA</strong>, an attacker with network access to the management interface could retrieve that secret.</p>



<p>Using the exposed credentials, an attacker may obtain administrator-level access to the RabbitMQ server, allowing them to manage messages, queues, users, and broker settings.</p>



<p>The second vulnerability, <strong>CVE-2026-57221</strong>, affects permission validation within RabbitMQ. Although less severe, it allows authenticated users with limited privileges to discover queues, exchanges, and usage statistics that they should not normally be able to access. In shared or multi-tenant environments, this information could help attackers gather intelligence for future attacks.</p>



<h3 class="wp-block-heading">Recommended Security Measures</h3>



<p>Both vulnerabilities have been fixed in <strong>RabbitMQ 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15</strong>.</p>



<p>Organizations should take the following steps to protect their RabbitMQ deployments:</p>



<ul class="wp-block-list">
<li>Update RabbitMQ to a supported patched version immediately.</li>



<li>Rotate OAuth client secrets after applying updates.</li>



<li>Restrict access to the RabbitMQ management interface (port <strong>15672</strong>) and avoid exposing it to public networks.</li>



<li>Isolate tenants using separate virtual hosts instead of shared environments.</li>



<li>Review container images and Helm charts to ensure they are not using vulnerable RabbitMQ versions.</li>



<li>Monitor RabbitMQ systems for unusual administrative activity or unauthorized access attempts.</li>
</ul>



<p>These vulnerabilities highlight the importance of securing management interfaces and regularly updating infrastructure components. Prompt patching, strong access controls, and continuous security monitoring remain essential for protecting messaging platforms and the applications that depend on them.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/rabbitmq-oauth-flaw/">RabbitMQ OAuth Bug Allows Unauthorized Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/rabbitmq-oauth-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GitHub Signature Flaw Enables Duplicate Verified Commits</title>
		<link>https://firsthackersnews.com/github-signature-flaw/</link>
					<comments>https://firsthackersnews.com/github-signature-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 21:24:56 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CI/CD Security]]></category>
		<category><![CDATA[Code Signing]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[ECDSA]]></category>
		<category><![CDATA[EdDSA]]></category>
		<category><![CDATA[Git Security]]></category>
		<category><![CDATA[github]]></category>
		<category><![CDATA[OpenPGP]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[S/MIME]]></category>
		<category><![CDATA[Secure Development]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[Signature Malleability]]></category>
		<category><![CDATA[Software Integrity]]></category>
		<category><![CDATA[software supply chain]]></category>
		<category><![CDATA[supply chain security]]></category>
		<category><![CDATA[Verified Commits]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11994</guid>

					<description><![CDATA[<p>A recently disclosed security finding has revealed that attackers can create duplicate &#8220;Verified&#8221; GitHub commits by exploiting a</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/github-signature-flaw/">GitHub Signature Flaw Enables Duplicate Verified Commits</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A recently disclosed security finding has revealed that attackers can create duplicate <strong>&#8220;Verified&#8221;</strong> GitHub commits by exploiting a technique known as <strong>signature malleability</strong>. Although the duplicated commit is assigned a different hash, it contains the same source code, remains cryptographically valid, and continues to display GitHub&#8217;s trusted <strong>&#8220;Verified&#8221;</strong> badge.</p>



<p>This discovery challenges a long-standing assumption within Git—that a verified commit hash uniquely identifies a specific piece of signed code. As a result, organizations that rely on commit hashes for software integrity, dependency management, CI/CD validation, or software supply chain security should carefully evaluate the potential impact of this issue.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>Git generates a unique hash for every commit using multiple components, including the source code, author and committer information, commit message, parent commit, and the embedded digital signature.</p>



<p>Under normal circumstances, modifying any part of a commit results in a completely different hash. However, researchers found that certain digital signature formats allow the signature&#8217;s encoded representation to be modified without affecting its cryptographic validity.</p>



<p>By changing only the encoding of the signature—not the source code or commit metadata—attackers can generate a new commit hash while preserving the same content and a valid signature. GitHub continues to verify the modified commit successfully and displays the familiar <strong>&#8220;Verified&#8221;</strong> badge.</p>



<p>As a result, two different commit hashes can represent the same code, making both appear as separate trusted commits.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>Many organizations use commit hashes as trusted identifiers throughout their software development lifecycle. Security tools, CI/CD pipelines, dependency management systems, and software supply chain controls often assume that every verified commit hash is unique and immutable.</p>



<p>This research demonstrates that the assumption may not always hold true.</p>



<p>An attacker could recreate an existing verified commit with a different hash, potentially bypassing security controls that rely solely on commit hashes. Systems designed to block malicious commits, enforce dependency pinning, or verify source code integrity may fail to recognize the duplicated commit because it appears as a new trusted object.</p>



<h2 class="wp-block-heading"><strong>Research Findings</strong></h2>



<p>Security researcher <strong>Jacob Ginesin</strong> demonstrated several practical techniques affecting multiple GitHub-supported signature formats, including:</p>



<ul class="wp-block-list">
<li>ECDSA</li>



<li>RSA (OpenPGP)</li>



<li>EdDSA</li>



<li>S/MIME/CMS</li>
</ul>



<p>The research shows that GitHub currently accepts these modified signatures during verification and continues to mark the resulting commits as <strong>Verified</strong>, even though their hashes differ from the originals.</p>



<p>Since GitHub validates the cryptographic signature rather than enforcing a canonical signature encoding, these modified commits continue to pass the verification process successfully.</p>



<h2 class="wp-block-heading"><strong>Potential Impact</strong></h2>



<p>The implications extend beyond individual repositories and may affect broader software supply chain security practices.</p>



<p>Potential risks include:</p>



<ul class="wp-block-list">
<li>Bypassing hash-based security controls.</li>



<li>Circumventing commit blocklists by generating new verified hashes.</li>



<li>Misleading dependency pinning mechanisms that rely on commit hashes.</li>



<li>Creating confusion during repository comparisons and code reviews.</li>



<li>Weakening software supply chain verification processes.</li>



<li>Affecting reproducible build and software provenance frameworks that treat commit hashes as trusted identifiers.</li>
</ul>



<p>Because Git commits are linked through parent commit hashes, modifying a signed commit also changes the hashes of all subsequent commits, allowing attackers to generate an entirely new yet valid-looking commit history.</p>



<h2 class="wp-block-heading"><strong>Security Recommendations</strong></h2>



<p>Until stronger mitigations are introduced, organizations should avoid relying solely on commit hashes when validating software integrity.</p>



<p>Consider adopting the following security practices:</p>



<ul class="wp-block-list">
<li>Validate both commit content and digital signatures instead of relying only on commit hashes.</li>



<li>Monitor repositories for unexpected duplicate verified commits.</li>



<li>Strengthen CI/CD validation with multiple layers of verification.</li>



<li>Review dependency pinning strategies that depend exclusively on commit hashes.</li>



<li>Keep GitHub security features and repository protection settings up to date.</li>



<li>Monitor security advisories and implement recommended mitigations as they become available.</li>
</ul>



<h2 class="wp-block-heading"><strong>Final Thoughts</strong></h2>



<p>This research serves as an important reminder that a <strong>&#8220;Verified&#8221;</strong> badge alone should not be considered the sole indicator of trust. While digital signatures remain a critical component of software integrity, organizations should implement layered verification processes that validate both the authenticity of the signature and the integrity of the underlying code.</p>



<p>As software supply chain attacks continue to evolve, strengthening repository security, enhancing CI/CD validation, and adopting defense-in-depth strategies will be essential to maintaining trust in modern software development workflows.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/github-signature-flaw/">GitHub Signature Flaw Enables Duplicate Verified Commits</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/github-signature-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>SindriKit 1.3.0 Bypasses EDR Security</title>
		<link>https://firsthackersnews.com/sindrikit-1-3-0/</link>
					<comments>https://firsthackersnews.com/sindrikit-1-3-0/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 17:33:25 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11990</guid>

					<description><![CDATA[<p>A new version of SindriKit (1.3.0) introduces advanced techniques designed to evade modern Endpoint Detection and Response (EDR)</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/sindrikit-1-3-0/">SindriKit 1.3.0 Bypasses EDR Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A new version of <strong>SindriKit (1.3.0)</strong> introduces advanced techniques designed to evade modern <strong>Endpoint Detection and Response (EDR)</strong> solutions.</p>



<p>Earlier versions focused on using <strong>indirect system calls</strong> to bypass user-mode API hooks. However, today&#8217;s EDR platforms have evolved and now analyze <strong>call stacks</strong>, <strong>Event Tracing for Windows (ETW)</strong>, and execution flow to identify suspicious behavior.</p>



<p>To counter these detection methods, SindriKit 1.3.0 adds <strong>dynamic call stack spoofing</strong>, allowing malicious execution to appear as though it originated from legitimate Windows components.</p>



<h2 class="wp-block-heading">How the Technique Works</h2>



<p>Modern EDR solutions don&#8217;t just monitor API calls—they also inspect the execution path that leads to a system call.</p>



<p>Even when malware invokes a legitimate Windows function, security products can detect abnormal return addresses or unexpected call chains, revealing malicious activity.</p>



<p>SindriKit 1.3.0 addresses this by generating a legitimate-looking call stack before executing a system call.</p>



<p>The framework performs several steps automatically, including:</p>



<ul class="wp-block-list">
<li>Parsing Windows exception handling information.</li>



<li>Identifying legitimate functions with large stack allocations (&#8220;Fat Frames&#8221;).</li>



<li>Selecting trusted return addresses from Windows modules.</li>



<li>Randomizing stack layouts to avoid predictable execution patterns.</li>
</ul>



<p>This allows the execution flow to closely resemble normal Windows behavior.</p>



<h2 class="wp-block-heading">Call Stack Layout</h2>



<p>Researchers explained that SindriKit&#8217;s <strong>MASM-based loader</strong> builds a carefully crafted <strong>JMP trampoline</strong> that creates a legitimate-looking call stack. This enables the execution flow to appear normal to both the Windows processor and EDR solutions that analyze call stacks.</p>



<p>; Top-of-stack spoofing layout </p>



<p>mov [rsp+0], r8 ; Trampoline Gadget (RET in Fat Frame) </p>



<p>lea rax, SyscallCleanup</p>



<p>mov [rsp+8], rax ; True return address (payload cleanup)</p>



<p>mov rax, [rbp+16] ; Original caller return address</p>



<p>mov [rsp+r12+8], rax ; r12 = spoof_frame_size</p>



<p>Instead of returning directly to attacker-controlled memory, execution passes through legitimate Windows stack frames. This makes the call chain appear more consistent during analysis and reduces the likelihood of detection by security products that inspect stack behavior.</p>



<h2 class="wp-block-heading">Randomization Improves Stealth</h2>



<p>Another key enhancement in SindriKit 1.3.0 is the use of randomization.</p>



<p>Rather than using the same stack layout every time, the framework dynamically selects different legitimate functions during execution.</p>



<p>This helps ensure that each system call follows a slightly different path, making behavioral detection more difficult and reducing the effectiveness of static call stack signatures.</p>



<p>After the system call finishes, execution first returns to the <strong>Trampoline Gadget</strong>, which immediately redirects control to <strong>SyscallCleanup</strong> inside the payload.</p>



<p>At the same time, Windows rebuilds the call stack using its exception handling information, making the execution path appear legitimate during stack analysis. This helps the spoofed call stack blend in with normal Windows activity.</p>



<p>On <strong>64-bit (x64)</strong> systems, SindriKit dynamically creates this spoofed call stack for each execution. On <strong>32-bit (x86)</strong> systems, where the required exception metadata is unavailable, the framework instead relies on predefined Windows functions and trusted return instructions to achieve a similar result.</p>



<h2 class="wp-block-heading">Security Recommendations</h2>



<p>Organizations should strengthen their defenses against advanced EDR evasion techniques by:</p>



<ul class="wp-block-list">
<li>Keeping EDR and endpoint security solutions up to date.</li>



<li>Monitoring abnormal syscall and process execution behavior.</li>



<li>Detecting unusual memory manipulation and call stack anomalies.</li>



<li>Enabling ETW and behavioral monitoring where supported.</li>



<li>Combining multiple detection methods instead of relying solely on signature-based protection.</li>



<li>Regularly reviewing endpoint telemetry for suspicious activity.</li>
</ul>



<p>The release of <strong>SindriKit 1.3.0</strong> demonstrates how offensive security techniques continue to evolve alongside defensive technologies. As attackers adopt increasingly sophisticated evasion methods, organizations should focus on layered detection strategies and behavioral analysis to identify threats that traditional security mechanisms may overlook.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/sindrikit-1-3-0/">SindriKit 1.3.0 Bypasses EDR Security</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/sindrikit-1-3-0/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Parrot 7.3 Launches with New Features</title>
		<link>https://firsthackersnews.com/parrot-7-3/</link>
					<comments>https://firsthackersnews.com/parrot-7-3/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Sun, 05 Jul 2026 17:42:17 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Bettercap]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Ethical Hacking]]></category>
		<category><![CDATA[Ghidra]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Linux Update]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Parrot 7.3]]></category>
		<category><![CDATA[Parrot OS]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[SQLMap]]></category>
		<category><![CDATA[Vagrant]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11974</guid>

					<description><![CDATA[<p>The Parrot Security team has released Parrot 7.3, focusing on performance, usability, and overall system improvements instead of</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/parrot-7-3/">Parrot 7.3 Launches with New Features</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The <strong>Parrot Security</strong> team has released <strong>Parrot 7.3</strong>, focusing on performance, usability, and overall system improvements instead of adding a large number of new security tools.</p>



<p>The update introduces a redesigned menu system, faster package handling, optimized builds for modern processors, official Vagrant support, and several quality-of-life improvements aimed at making Parrot OS easier to use for both security professionals and everyday users.</p>



<h2 class="wp-block-heading"><strong>Parrot 7.3 -Performance Improvements</strong></h2>



<p>One of the biggest highlights of Parrot 7.3 is improved performance on newer hardware.</p>



<p>The release includes optional packages optimized for modern <strong>x86-64-v3</strong> and <strong>ARMv8.2-A</strong> processors, allowing supported systems to achieve noticeable performance gains during resource-intensive tasks.</p>



<p>These optimizations benefit applications such as:</p>



<ul class="wp-block-list">
<li>FFmpeg</li>



<li>Inkscape</li>



<li>NumPy</li>



<li>Shared libraries</li>



<li>Programming language runtimes</li>
</ul>



<p>To maintain compatibility, core system components continue using standard builds, while hardware compatibility checks ensure optimized packages are installed only on supported processors.</p>



<h2 class="wp-block-heading"><strong>Redesigned Menu System</strong></h2>



<p>Parrot 7.3 replaces its previous shell-based launcher with a new menu system written in <strong>Go</strong>.</p>



<p>The updated launcher simplifies application management and allows users to install supported tools directly from the desktop menu without opening the terminal.</p>



<p>The new menu also offers:</p>



<ul class="wp-block-list">
<li>Faster application launching</li>



<li>Automatic menu updates</li>



<li>Removal of duplicate launcher entries</li>



<li>Cleaner navigation across installed and available tools</li>
</ul>



<p>The goal is to provide a smoother experience for both new users and experienced penetration testers.</p>



<h2 class="wp-block-heading"><strong>Official Vagrant Support</strong></h2>



<p>Another major addition is official <strong>Vagrant</strong> support for the Home and Security editions.</p>



<p>The preconfigured Vagrant boxes allow users to quickly deploy consistent Parrot environments for:</p>



<ul class="wp-block-list">
<li>Security testing</li>



<li>Training labs</li>



<li>Development</li>



<li>CI/CD environments</li>



<li>Team collaboration</li>
</ul>



<p>This makes it easier to reproduce testing environments across different systems.</p>



<h2 class="wp-block-heading"><strong>Improved Privacy and Smaller Images</strong></h2>



<p>Parrot 7.3 also introduces a redesigned Firefox start page that respects user privacy.</p>



<p>Users can choose their preferred search engine, including:</p>



<ul class="wp-block-list">
<li>DuckDuckGo</li>



<li>Qwant</li>



<li>Google</li>
</ul>



<p>According to the Parrot team, the new page does not collect user data, reflecting the project&#8217;s privacy-focused approach.</p>



<p>The release also reduces the number of preinstalled packages in the Home and Security editions, resulting in smaller installation images and a lighter operating system.</p>



<h2 class="wp-block-heading"><strong>Updated Security Tools</strong></h2>



<p>Parrot 7.3 ships with updated software packages to keep security professionals working with the latest tools.</p>



<p>Some notable updates include:</p>



<ul class="wp-block-list">
<li>Linux Kernel 7.0.9</li>



<li>Metasploit 6.4.136</li>



<li>Ghidra 12.0.4</li>



<li>SQLMap 1.10.4</li>



<li>Bettercap 2.41.5</li>
</ul>



<p>Rather than introducing dozens of new tools, <strong>Parrot 7.3</strong> focuses on refining the overall user experience. With improved performance, a redesigned menu system, official Vagrant support, updated security tools, and a lighter installation, the release delivers meaningful improvements for penetration testers, security researchers, and Linux enthusiasts alike.<audio autoplay=""></audio></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/parrot-7-3/">Parrot 7.3 Launches with New Features</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/parrot-7-3/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>India Bans Apps Used to Stop E-Rickshaws Remotely</title>
		<link>https://firsthackersnews.com/e-rickshaw-apps/</link>
					<comments>https://firsthackersnews.com/e-rickshaw-apps/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Sun, 05 Jul 2026 17:32:53 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[App Ban]]></category>
		<category><![CDATA[Battery Management System]]></category>
		<category><![CDATA[BMS]]></category>
		<category><![CDATA[Connected Vehicles]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[E-Rickshaw]]></category>
		<category><![CDATA[Electric Vehicles]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[IoT Security]]></category>
		<category><![CDATA[mobile apps]]></category>
		<category><![CDATA[Passenger Safety]]></category>
		<category><![CDATA[Transportation Security]]></category>
		<category><![CDATA[Vehicle Security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11970</guid>

					<description><![CDATA[<p>The Indian government has directed Google and Apple to remove three mobile applications—BAT-BMS, Lossigy, and Epoch-i-ion—after they were</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/e-rickshaw-apps/">India Bans Apps Used to Stop E-Rickshaws Remotely</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>The Indian government has directed <strong>Google</strong> and <strong>Apple</strong> to remove three mobile applications—<strong>BAT-BMS</strong>, <strong>Lossigy</strong>, and <strong>Epoch-i-ion</strong>—after they were allegedly misused to remotely disable e-rickshaws while they were carrying passengers.</p>



<p>The decision comes after videos circulated online showing users remotely shutting down battery-powered three-wheelers, raising serious concerns about passenger and road safety.</p>



<p>Authorities have also warned that any other apps offering similar unsafe remote-control capabilities could face similar action.</p>



<h2 class="wp-block-heading"><strong>Why Were These Apps Removed?</strong></h2>



<p>The apps were originally developed as <strong>Battery Management System (BMS)</strong> tools for electric vehicles.</p>



<p>Their intended purpose was to help:</p>



<ul class="wp-block-list">
<li>Monitor battery health and charging status</li>



<li>Track vehicle location</li>



<li>Manage fleet operations</li>



<li>Disable vehicles in cases of theft or loan default</li>
</ul>



<p>However, authorities found that the remote shutdown feature was allegedly being misused to stop vehicles without the driver&#8217;s permission.</p>



<h2 class="wp-block-heading"><strong>How the Apps Were Misused</strong></h2>



<p>According to reports, some users were able to remotely disable nearby e-rickshaws using the connected battery management system.</p>



<p>Researchers believe the issue was caused by weak access controls, allowing unauthorized users with access credentials to send remote shutdown commands.</p>



<p>This meant that features designed for fleet management could potentially be misused by:</p>



<ul class="wp-block-list">
<li>Unauthorized individuals</li>



<li>Rival financiers</li>



<li>Disgruntled employees</li>



<li>Malicious actors</li>



<li>Pranksters</li>
</ul>



<p>Such actions could interrupt journeys and create serious safety risks for both drivers and passengers.</p>



<h2 class="wp-block-heading"><strong>Security Concerns</strong></h2>



<p>The incident highlights growing security challenges within Internet of Things (IoT)-enabled electric vehicles.</p>



<p>Researchers note that many low-cost electric vehicle platforms prioritize functionality over security, leaving connected systems vulnerable to misuse.</p>



<p>Some of the reported concerns include:</p>



<ul class="wp-block-list">
<li>Weak authentication mechanisms</li>



<li>Shared or leaked login credentials</li>



<li>Insufficient access controls</li>



<li>Lack of driver authorization</li>



<li>Remote shutdown without safety checks</li>
</ul>



<p>Without proper safeguards, features intended to improve vehicle management can become potential security risks.</p>



<h2 class="wp-block-heading"><strong>Government Response</strong></h2>



<p>Following reports of misuse, the government instructed Google and Apple to remove the affected applications from their respective app stores.</p>



<p>Officials also indicated that additional apps found enabling similar remote vehicle shutdown capabilities could face the same action.</p>



<p>The move reflects increasing efforts to improve the security of connected transportation technologies and protect public safety.</p>



<h2 class="wp-block-heading"><strong>Recommendations for Fleet Operators</strong></h2>



<p>Organizations using connected Battery Management Systems should strengthen their security by:</p>



<ul class="wp-block-list">
<li>Enabling multi-factor authentication (MFA)</li>



<li>Restricting access to authorized users only</li>



<li>Preventing remote shutdown while vehicles are moving</li>



<li>Maintaining audit logs for remote commands</li>



<li>Conducting regular security assessments of BMS platforms</li>



<li>Securing backend APIs and user credentials</li>
</ul>



<p>As connected electric vehicles become more common, securing remote management features will be essential to prevent misuse and ensure passenger safety.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/e-rickshaw-apps/">India Bans Apps Used to Stop E-Rickshaws Remotely</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/e-rickshaw-apps/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Malicious Extension Swaps Crypto Wallet Addresses</title>
		<link>https://firsthackersnews.com/malicious-browser-extension-crypto/</link>
					<comments>https://firsthackersnews.com/malicious-browser-extension-crypto/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 01 Jul 2026 17:15:03 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Bitcoin]]></category>
		<category><![CDATA[Blockchain security]]></category>
		<category><![CDATA[browser extension]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[chromium]]></category>
		<category><![CDATA[Crypto theft]]></category>
		<category><![CDATA[crypto wallet]]></category>
		<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Ethereum]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[malicious browser extension]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11944</guid>

					<description><![CDATA[<p>Cybersecurity researchers have uncovered a sophisticated campaign distributing a malicious Chromium-based browser extension that silently replaces cryptocurrency wallet</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/malicious-browser-extension-crypto/">Malicious Extension Swaps Crypto Wallet Addresses</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Cybersecurity researchers have uncovered a sophisticated campaign distributing a malicious Chromium-based browser extension that silently replaces cryptocurrency wallet addresses during transactions. Disguised as a lightweight <strong>&#8220;Google Notes&#8221;</strong> extension, the malware is designed to steal digital assets without alerting the victim.</p>



<p>The attack is delivered through unsigned installers written in both <strong>.NET</strong> and <strong>Golang</strong>. Instead of installing the extension through an official browser store, the malware directly modifies Chromium browser files to install the extension and maintain persistence.</p>



<h2 class="wp-block-heading"><strong>How the Attack Works</strong></h2>



<p>Once executed, the installer searches for Chromium-based browsers such as <strong>Google Chrome, Microsoft Edge, Brave</strong>, and other compatible browsers. It terminates running browser processes and modifies the <strong>Preferences</strong> and <strong>Secure Preferences</strong> files to register the malicious extension.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="818" src="https://firsthackersnews.com/wp-content/uploads/2026/07/image.png" alt="" class="wp-image-11945" srcset="https://firsthackersnews.com/wp-content/uploads/2026/07/image-177x142.png 177w, https://firsthackersnews.com/wp-content/uploads/2026/07/image-300x240.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/07/image-768x614.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/07/image.png 1024w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><em>Source : McAfee</em></figcaption></figure>



<p>Researchers found that the malware recalculates browser integrity values, allowing the extension to bypass certain security checks on older Chromium versions. On newer versions, the attackers rely on social engineering or developer mode to enable the extension. After installation, the installer removes itself, leaving very few traces on the infected system.</p>



<p>Unlike traditional malware that connects to a hardcoded command-and-control server, the extension uses an <strong>EtherHiding</strong> technique. It queries a public blockchain RPC endpoint and retrieves an encoded value from a smart contract, which is decoded at runtime to obtain the active backend server. This approach allows attackers to change their infrastructure without updating the malware itself, making detection and takedown more difficult.</p>



<h2 class="wp-block-heading"><strong>Wallet Address Replacement and Detection</strong></h2>



<p>The extension requests broad permissions, including access to websites, browsing history, and clipboard data. It continuously monitors copy-and-paste activity and uses cryptocurrency-specific patterns to identify wallet addresses for multiple blockchains, including:</p>



<ul class="wp-block-list">
<li>Bitcoin (BTC)</li>



<li>Ethereum (ETH)</li>



<li>Bitcoin Cash (BCH)</li>



<li>Ripple (XRP)</li>



<li>Dash (DASH)</li>



<li>Solana (SOL)</li>
</ul>



<p>When a wallet address is copied, the extension sends it to the attacker&#8217;s backend using an embedded API key. The server responds with an attacker-controlled wallet address, which immediately replaces the original address in the clipboard. If the victim pastes the address without verifying it, the cryptocurrency is transferred directly to the attacker&#8217;s wallet.</p>



<p>Researchers also found that the installer contains embedded configuration data, including API keys, extension settings, supported wallet types, and blockchain RPC endpoints. The malicious extension is downloaded separately during installation, allowing attackers to update components without modifying the installer.</p>



<p>The campaign has affected users across multiple regions, with researchers observing a notable concentration of infections in India, suggesting opportunistic targeting of cryptocurrency users rather than a region-specific operation.</p>



<p>To reduce the risk of compromise, users should install browser extensions only from official stores, avoid running unsigned installers, carefully review requested permissions, and always verify the first and last few characters of a cryptocurrency wallet address before completing a transaction. </p>



<p>Security teams should also monitor for unauthorized changes to Chromium <strong>Secure Preferences</strong> files, unexpected browser configuration modifications, and unusual blockchain RPC traffic associated with <strong>EtherHiding</strong> infrastructure.</p>



<h2 class="wp-block-heading"><strong>IOCs</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Type</strong>&nbsp;</td><td><strong>Category</strong>&nbsp;</td><td><strong>Value</strong>&nbsp;</td></tr><tr><td>SHA-256&nbsp;</td><td>.NET Installer (BaseZipInstaller)&nbsp;</td><td>2735e12030c195fb5454e4736c51b55b59664b93cae9f4bd5317afcd9c2af0bf&nbsp;053620962047f50a91c6e8d1a6519eccc41fab51473f033086b4d816abe8bcb0&nbsp;&nbsp;</td></tr><tr><td>SHA-256&nbsp;</td><td>Golang-compiled Installer Variant&nbsp;</td><td>11be4c47ff049322de41743f62544cafd32d67e24ad653b7ebedf8ebd63e0962  &nbsp;1432393691b415d0cd4680d9cee73e60896fbe63300d9f0355c96e91817e4b1d  &nbsp;</td></tr><tr><td>URL&nbsp;</td><td>Payload distribution&nbsp;</td><td>hxxps://google-services[.]cc/base[.]zip&nbsp;</td></tr><tr><td>Domain&nbsp;</td><td>Command-and-Control (resolved via smart contract)&nbsp;</td><td>devops-offensive[.]cc&nbsp;Zebregts[.]com&nbsp;</td></tr><tr><td>BTC wallet&nbsp;</td><td>Crypto wallet&nbsp;</td><td>3JvDBvKbS6YYMKjV3R9e9Zfd67f467fNLy&nbsp;1BbhVBxpniuZuAL1gGZnEMdQhmz9JGWpyT&nbsp;3AcPNVh7NyESwX3ECymy3rkdH4Ke2c26Tj&nbsp;1BVTrB47erypG3tevi1U9Fv6BbNUBEiuiX&nbsp;</td></tr><tr><td>Artifact&nbsp;</td><td>Sideload target&nbsp;</td><td>Chromium Secure Preferences file (Chrome, Edge, Brave, Opera profiles)&nbsp;</td></tr><tr><td>Extension files&nbsp;</td><td>manifest.json&nbsp;&nbsp;crypto-patterns.js&nbsp;&nbsp;Interceptor.js&nbsp;&nbsp;content-script.j&nbsp;&nbsp;&nbsp;cache.js&nbsp;&nbsp;&nbsp;domain-resolver.js&nbsp;&nbsp;service-worker.js&nbsp;&nbsp;api-client.js&nbsp;</td><td>ed2599d6a8f30d5eaf14ad7f855aece0acdf7efa4a148eb18e4d9f0d8e2cd90c&nbsp;&nbsp;daf82c67e8e5df6bbd5370172ac9374aa7dce48af05496e8ec3dba7b602c619b&nbsp;&nbsp;6eb2f07265dd95cacd39dfcf0705786b97f3e173cf4e9b3dfe7bad141c9a9dd5&nbsp;&nbsp;a2ffdbedc5c9f5400a2b1cf5d35f5ec1df06a74d0345f1035bcf75d36ed73e01&nbsp;&nbsp;&nbsp;eb84ba4a0cd95655a021865d4fec93ae3393f86cc9848810ed0b49035b1c5e2c&nbsp;&nbsp;6aaba685669d779ef8be8f7f4231096cfafd0ef386f3897c5e2106c177724fc8&nbsp;&nbsp;&nbsp;2599064901308a97540af29197ed0b38702bbee38d6dbbfa61cf9eb5878353f3&nbsp;&nbsp;ab450927b37e1b68e2be68832c354ac600e86e2545a904d4ca0ea283f2600cc2&nbsp;&nbsp;&nbsp;</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/malicious-browser-extension-crypto/">Malicious Extension Swaps Crypto Wallet Addresses</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/malicious-browser-extension-crypto/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Introduces Usernames for Private Messaging</title>
		<link>https://firsthackersnews.com/whatsapp-usernames/</link>
					<comments>https://firsthackersnews.com/whatsapp-usernames/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 22:17:34 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Chat Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Digital Privacy]]></category>
		<category><![CDATA[Messaging]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[Online Privacy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Privacy Features]]></category>
		<category><![CDATA[Secure Messaging]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Technology News]]></category>
		<category><![CDATA[whatsapp]]></category>
		<category><![CDATA[WhatsApp Usernames]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11937</guid>

					<description><![CDATA[<p>WhatsApp has introduced a new username feature designed to improve user privacy by allowing people to communicate without</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-usernames/">WhatsApp Introduces Usernames for Private Messaging</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp has introduced a new username feature designed to improve user privacy by allowing people to communicate without sharing their phone numbers. The update marks one of the platform&#8217;s most significant privacy enhancements, giving users greater control over how they connect with others.</p>



<p>Instead of exchanging phone numbers, users will be able to share a unique username when starting new conversations. This feature is especially useful when joining community groups, networking at events, or interacting with people for the first time.</p>



<p>The rollout is being introduced in phases, with users able to reserve their preferred usernames before the feature becomes widely available.</p>



<h2 class="wp-block-heading"><strong>How the Username Feature Works</strong></h2>



<p>Once the feature is enabled, new contacts will only see a user&#8217;s username instead of their phone number. Existing chats and contacts will continue to function normally, and users who prefer sharing phone numbers can continue using WhatsApp as they always have.</p>



<p>To prevent impersonation and abuse, WhatsApp has introduced several rules for creating usernames:</p>



<ul class="wp-block-list">
<li>Usernames must be <strong>3–35 characters</strong> long.</li>



<li>Only lowercase letters, numbers, periods, and underscores are allowed.</li>



<li>Every username must include at least one letter.</li>



<li>Usernames that resemble website domains, such as <strong>.com</strong> or <strong>.in</strong>, are not permitted.</li>



<li>Each username must be unique, and users can choose to match their existing Instagram or Facebook handle for consistent branding.</li>
</ul>



<p>WhatsApp has also added an optional <strong>username key</strong>, a four-digit PIN-like code that provides an additional layer of privacy. New contacts must enter this code before they can send a message, helping reduce spam and unwanted conversations. Existing contacts are not affected by this requirement.</p>



<h2 class="wp-block-heading"><strong>Improved Privacy and User Protection</strong></h2>



<p>Unlike many social media platforms, WhatsApp usernames are not searchable through a public directory. Users cannot browse or discover other usernames unless they already know the exact handle, significantly reducing unsolicited messages and unwanted contact.</p>



<p>The feature is available across Android, iOS, Windows, and WhatsApp Web as the rollout expands globally. Users can reserve a username by navigating to <strong>Settings → Account → Username</strong> on the latest version of the app. WhatsApp also provides username suggestions if a preferred handle has already been taken.</p>



<p>The new system is particularly beneficial for creators, businesses, and organizations, allowing them to use the same username across WhatsApp, Instagram, and Facebook for a consistent online identity.</p>



<p>By moving from phone number-based communication to username-based messaging, WhatsApp is strengthening user privacy while reducing unnecessary exposure of personal contact information. The update also brings the platform closer to privacy-focused messaging services that have long supported handle-based communication.</p>



<p></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-usernames/">WhatsApp Introduces Usernames for Private Messaging</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-usernames/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
