<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tips &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/tips/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Wed, 05 Aug 2026 20:58:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Tips &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Top 10 Phishing Email Red Flags You Should Never Ignore</title>
		<link>https://firsthackersnews.com/top-10-phishing-email-red-flags/</link>
					<comments>https://firsthackersnews.com/top-10-phishing-email-red-flags/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 20:58:37 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Cyber Awareness]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Online Safety]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[phishing emails]]></category>
		<category><![CDATA[Scam Prevention]]></category>
		<category><![CDATA[social engineering]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12141</guid>

					<description><![CDATA[<p>Phishing remains one of the most successful cyberattack techniques because it exploits human trust rather than technical vulnerabilities.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/top-10-phishing-email-red-flags/">Top 10 Phishing Email Red Flags You Should Never Ignore</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Phishing remains one of the most successful cyberattack techniques because it exploits human trust rather than technical vulnerabilities. Every day, attackers send fraudulent emails designed to steal credentials, distribute malware, or trick recipients into revealing sensitive information.</p>



<p>Understanding the warning signs of a phishing email is one of the most effective ways to reduce cyber risk. Below are ten common indicators that every individual and organization should recognize.</p>



<h2 class="wp-block-heading"><strong>1. Suspicious Sender Address</strong></h2>



<p>The sender&#8217;s email address is one of the first things to verify. Cybercriminals often register domains that closely resemble legitimate organizations by changing a single character or using uncommon domain extensions.</p>



<p>Always verify the sender before opening attachments or clicking links.</p>



<h2 class="wp-block-heading"><strong>2. Urgent or Fear-Inducing Messages</strong></h2>



<p>Phishing emails frequently create a false sense of urgency to pressure recipients into acting quickly.</p>



<p>Examples include:</p>



<ul class="wp-block-list">
<li>Your account has been suspended.</li>



<li>Immediate action required.</li>



<li>Your payment has failed.</li>



<li>Verify your identity now.</li>
</ul>



<p>Legitimate organizations rarely demand immediate action without providing alternative ways to verify the request.</p>



<h2 class="wp-block-heading"><strong>3. Suspicious Links</strong></h2>



<p>Before clicking any hyperlink, hover your cursor over it to view its actual destination.</p>



<p>If the displayed URL differs from the official company website or contains unusual characters, it should be treated as suspicious.</p>



<p>When in doubt, access the website directly through your browser instead of using the email link.</p>



<h2 class="wp-block-heading"><strong>4. Requests for Sensitive Information</strong></h2>



<p>Legitimate businesses do not typically request passwords, banking information, one-time passcodes, or confidential personal data through email.</p>



<p>Any message asking for sensitive information should be independently verified before responding.</p>



<h2 class="wp-block-heading"><strong>5. Poor Grammar and Unprofessional Formatting</strong></h2>



<p>Many phishing emails contain spelling mistakes, grammatical errors, inconsistent fonts, or unusual formatting.</p>



<p>Although modern phishing campaigns have become more convincing, poor language quality remains a common warning sign.</p>



<h2 class="wp-block-heading"><strong>6. Unexpected Attachments</strong></h2>



<p>Opening unexpected attachments can result in malware infections, ransomware attacks, or credential theft.</p>



<p>Be especially cautious with file types such as:</p>



<ul class="wp-block-list">
<li>ZIP</li>



<li>EXE</li>



<li>ISO</li>



<li>JS</li>



<li>DOCM</li>



<li>HTML</li>
</ul>



<p>If you were not expecting the attachment, confirm its legitimacy with the sender before opening it.</p>



<h2 class="wp-block-heading"><strong>7. Generic Greetings</strong></h2>



<p>Instead of addressing recipients by name, phishing emails often use generic greetings such as:</p>



<ul class="wp-block-list">
<li>Dear Customer</li>



<li>Dear User</li>



<li>Valued Customer</li>



<li>Dear Member</li>
</ul>



<p>Many legitimate organizations personalize important communications using your registered name.</p>



<h2 class="wp-block-heading"><strong>8. Offers That Seem Too Good to Be True</strong></h2>



<p>Cybercriminals frequently lure victims with attractive offers such as:</p>



<ul class="wp-block-list">
<li>Free gift cards</li>



<li>Lottery winnings</li>



<li>Large discounts</li>



<li>Tax refunds</li>



<li>Prize claims</li>
</ul>



<p>If an offer appears unusually generous or unexpected, verify it through the organization&#8217;s official website.</p>



<h2 class="wp-block-heading"><strong>9. Fake Branding and Logos</strong></h2>



<p>Attackers often copy company logos, email templates, and branding to make phishing emails appear authentic.</p>



<p>A professional-looking email does not guarantee legitimacy. Always verify the sender&#8217;s address and carefully inspect links before interacting with the message.</p>



<h2 class="wp-block-heading"><strong>10. Unexpected Login or Verification Requests</strong></h2>



<p>Many phishing campaigns direct victims to fake login pages designed to steal usernames and passwords.</p>



<p>If you receive an unexpected request to sign in or verify your account, avoid using the link provided in the email. Instead, manually enter the official website address into your browser.</p>



<h2 class="wp-block-heading"><strong>Best Practices to Protect Against Phishing</strong></h2>



<p>Organizations and individuals can significantly reduce phishing risks by following these security practices:</p>



<ul class="wp-block-list">
<li>Enable Multi-Factor Authentication (MFA).</li>



<li>Use strong and unique passwords for every account.</li>



<li>Keep operating systems and applications up to date.</li>



<li>Verify unexpected requests before responding.</li>



<li>Avoid opening unknown attachments or clicking suspicious links.</li>



<li>Use email security filtering solutions.</li>



<li>Conduct regular cybersecurity awareness training.</li>



<li>Report suspected phishing emails to your IT or security team.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Phishing attacks continue to evolve, becoming more sophisticated and difficult to detect. However, most successful attacks still rely on users overlooking common warning signs.</p>



<p>By carefully verifying email senders, avoiding suspicious links and attachments, and following cybersecurity best practices, individuals and organizations can greatly reduce their exposure to phishing attacks and protect sensitive information from cybercriminals.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/top-10-phishing-email-red-flags/">Top 10 Phishing Email Red Flags You Should Never Ignore</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/top-10-phishing-email-red-flags/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Security Flaw Discovered in N-able N-central</title>
		<link>https://firsthackersnews.com/n-able-n-central-vulnerability/</link>
					<comments>https://firsthackersnews.com/n-able-n-central-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 17:19:05 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Reports]]></category>
		<category><![CDATA[authentication bypass]]></category>
		<category><![CDATA[CVE-2026-18577]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[Managed Service Provider]]></category>
		<category><![CDATA[MSP]]></category>
		<category><![CDATA[N-able]]></category>
		<category><![CDATA[N-central]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[remote monitoring]]></category>
		<category><![CDATA[RMM]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12114</guid>

					<description><![CDATA[<p>N-able has released an emergency hotfix for a critical authentication bypass vulnerability affecting its N-central Remote Monitoring and</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/n-able-n-central-vulnerability/">Critical Security Flaw Discovered in N-able N-central</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>N-able has released an emergency hotfix for a <strong>critical authentication bypass vulnerability</strong> affecting its <strong>N-central Remote Monitoring and Management (RMM)</strong> platform. The flaw, tracked as <strong>CVE-2026-18577</strong>, is being actively exploited and could allow attackers to gain unauthorized administrative access to vulnerable N-central servers.</p>



<p>The vulnerability affects <strong>N-central versions earlier than 2026.3.1.7</strong>, making it essential for organizations to update their systems immediately.</p>



<h2 class="wp-block-heading"><strong>Authentication Bypass Leads to Full Administrative Access</strong></h2>



<p>The vulnerability allows a remote attacker to bypass the authentication process without valid credentials and take control of user accounts.</p>



<p>Once administrative access is obtained, attackers can fully manage the N-central console and misuse its built-in management capabilities.</p>



<p>Since N-central is widely used by <strong>Managed Service Providers (MSPs)</strong> to manage customer environments, a successful attack could impact multiple organizations from a single compromised platform.</p>



<h2 class="wp-block-heading"><strong>Potential Impact on MSP Environments</strong></h2>



<p>A compromised N-central server can provide attackers with extensive control over managed devices.</p>



<p>Attackers may be able to:</p>



<ul class="wp-block-list">
<li>Execute scripts on managed systems.</li>



<li>Deploy malicious software or remote access tools.</li>



<li>Modify automation jobs and security policies.</li>



<li>Start remote support sessions.</li>



<li>Access critical servers such as domain controllers and file servers.</li>
</ul>



<p>Because N-central acts as a centralized management platform, compromising it could allow attackers to move across multiple customer environments.</p>



<h2 class="wp-block-heading"><strong>Active Exploitation Confirmed</strong></h2>



<p>Security researchers at Huntress confirmed that the vulnerability has already been exploited in real-world attacks.</p>



<p>The issue was initially associated with <strong>CVE-2026-18556</strong>, but N-able later clarified that <strong>CVE-2026-18577</strong> resulted from an incomplete fix, allowing attackers to bypass authentication and take over accounts.</p>



<p>To address the issue, N-able released <strong>N-central 2026.3 Hotfix 1 (version 2026.3.1.7)</strong> and recommends verifying installed versions instead of assuming earlier 2026.3 releases are protected.</p>



<h2 class="wp-block-heading"><strong>Recommended Security Measures</strong></h2>



<p>Organizations using N-central should take the following actions immediately:</p>



<ul class="wp-block-list">
<li>Upgrade to <strong>N-central version 2026.3.1.7</strong> or later.</li>



<li>Enable Multi-Factor Authentication (MFA) for administrative accounts.</li>



<li>Restrict access to the management console through VPNs or trusted networks.</li>



<li>Avoid exposing the N-central console directly to the internet.</li>



<li>Monitor audit logs and remote access activity for suspicious behavior.</li>
</ul>



<p>Security teams should also review authentication logs, unexpected remote sessions, and unusual administrative actions to determine whether their environment has been compromised.</p>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>The active exploitation of <strong>CVE-2026-18577</strong> highlights the risks associated with centralized remote management platforms. Since a single compromised N-central server can provide attackers with broad access across multiple customer environments, organizations should treat this vulnerability as a high priority. Applying the latest hotfix, strengthening access controls, and continuously monitoring administrative activity are critical steps to reducing the risk of compromise.</p>



<h2 class="wp-block-heading"><strong>Indicators of Compromise</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Type</th></tr></thead><tbody><tr><td><code>173.249.252[.]200</code></td><td>IP address</td></tr><tr><td><code>87.249.138[.]34</code></td><td>IP address</td></tr><tr><td><code>37.19.210[.]32</code></td><td>IP address</td></tr><tr><td><code>68.235.46[.]214</code></td><td>IP address</td></tr><tr><td><code>37.153.90[.]88</code></td><td>IP address</td></tr><tr><td><code>92.118.112[.]181</code></td><td>IP address</td></tr><tr><td><code>mousears.synology[.]me</code></td><td>Domain</td></tr><tr><td><code>wagoosh.direct.quickconnect[.]to</code></td><td>Domain</td></tr><tr><td><code>who-ripped-one.direct.quickconnect[.]to</code></td><td>Domain</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/n-able-n-central-vulnerability/">Critical Security Flaw Discovered in N-able N-central</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/n-able-n-central-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Linux FUSE Vulnerability Allows Root Access</title>
		<link>https://firsthackersnews.com/linux-fuse-vulnerability-root-access/</link>
					<comments>https://firsthackersnews.com/linux-fuse-vulnerability-root-access/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 18:36:33 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Linux Malware]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CVE-2026-31694]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[FUSE]]></category>
		<category><![CDATA[kernel vulnerability]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Linux security]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[root access]]></category>
		<category><![CDATA[system security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12007</guid>

					<description><![CDATA[<p>newly disclosed Linux kernel vulnerability, tracked as CVE-2026-31694, allows unprivileged local users to gain root privileges on affected</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/linux-fuse-vulnerability-root-access/">Linux FUSE Vulnerability Allows Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>newly disclosed <strong>Linux kernel vulnerability</strong>, tracked as <strong>CVE-2026-31694</strong>, allows unprivileged local users to gain <strong>root privileges</strong> on affected systems. The flaw exists in the Linux <strong>FUSE (Filesystem in Userspace)</strong> subsystem and affects the way directory entries are stored in the kernel page cache.</p>



<p>Researchers demonstrated that the vulnerability can be exploited to modify a <strong>SUID</strong> binary, such as <strong>/usr/bin/su</strong>, allowing attackers to execute code with root privileges. The issue affects <strong>Linux kernel v6.16-rc1 and later</strong> on systems using a <strong>4 KB page size</strong>.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>The flaw is caused by improper validation of directory entry sizes before they are copied into the kernel page cache. When an oversized directory entry is processed, it can trigger a small memory overflow beyond the page boundary.</p>



<p>Researchers showed that this overflow can corrupt cached executable files, including <strong>SUID</strong> binaries such as <strong>/usr/bin/su</strong>. When the modified binary is executed, the injected code runs with root privileges before the normal authentication process begins, allowing attackers to gain full control of the system.</p>



<p>To successfully exploit the vulnerability, an attacker must:</p>



<ul class="wp-block-list">
<li>Have local access to the system.</li>



<li>Be able to mount a FUSE filesystem.</li>



<li>Create a specially crafted directory entry.</li>



<li>Trigger the vulnerable code path through FUSE operations.</li>
</ul>



<h2 class="wp-block-heading"><strong>Affected Systems and Mitigation</strong></h2>



<p>The vulnerability becomes practically exploitable on <strong>Linux kernel v6.16-rc1 and later</strong>, after changes that increased the FUSE directory read buffer size. Systems using a <strong>4 KB page size</strong> are affected, while systems with larger page sizes are not vulnerable to this specific overflow.</p>



<p>The Linux kernel developers have released a patch that prevents oversized directory entries from being cached, eliminating the overflow condition.</p>



<p>Organizations should take the following steps to reduce risk:</p>



<ul class="wp-block-list">
<li>Update affected Linux systems with the latest kernel patches.</li>



<li>Restrict or disable unprivileged FUSE mounts where possible.</li>



<li>Disable unprivileged user namespaces if they are not required.</li>



<li>Remove the <strong>setuid</strong> permission from <strong>fusermount3</strong> when it is not needed.</li>



<li>Monitor systems for unauthorized local privilege escalation attempts.</li>



<li>Review systems for unusual activity involving FUSE filesystems and SUID binaries.</li>
</ul>



<p>Although this vulnerability requires local access, it highlights how a small flaw in a kernel subsystem can lead to complete system compromise. Prompt patching, restricting unnecessary FUSE access, and limiting local privileges are the most effective ways to reduce the risk of exploitation.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/linux-fuse-vulnerability-root-access/">Linux FUSE Vulnerability Allows Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/linux-fuse-vulnerability-root-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PRC-Linked Threat Actors Target REDCap Servers to Spy on U.S. Medical Research Organizations</title>
		<link>https://firsthackersnews.com/prc-redcap-medical-espionage/</link>
					<comments>https://firsthackersnews.com/prc-redcap-medical-espionage/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 12:38:01 +0000</pubDate>
				<category><![CDATA[AWS]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Vulnerability Reports]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Cyber Espionage]]></category>
		<category><![CDATA[Healthcare Cybersecurity]]></category>
		<category><![CDATA[INFINITERED Malware]]></category>
		<category><![CDATA[Medical Research Security]]></category>
		<category><![CDATA[PRC Threat Actors]]></category>
		<category><![CDATA[UNC6508]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11842</guid>

					<description><![CDATA[<p>PRC-linked hackers are targeting REDCap servers to conduct cyber espionage against U.S. medical research organizations. The campaign underscores the increasing risks facing healthcare, research, and academic sectors as threat actors seek access to valuable scientific and medical data.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/prc-redcap-medical-espionage/">PRC-Linked Threat Actors Target REDCap Servers to Spy on U.S. Medical Research Organizations</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers from Google Threat Intelligence Group (GTIG) uncovered a long-running cyber espionage campaign attributed to <strong>UNC6508</strong>, a PRC-linked threat actor that targeted medical, academic, and military research institutions across North America. The attackers remained undetected for more than a year while collecting sensitive information related to medical research, artificial intelligence, defense intelligence, cyber operations, and military strategy.</p>



<p>The campaign primarily focused on compromising <strong>REDCap (Research Electronic Data Capture)</strong> servers, a widely used platform for managing clinical research databases and surveys. After gaining access, the attackers deployed custom malware called <strong>INFINITERED</strong>, harvested credentials, established persistence, and later abused enterprise email compliance rules to exfiltrate sensitive communications.</p>



<h2 class="wp-block-heading">Campaign Overview</h2>



<p>The operation demonstrates a sophisticated attack chain combining exploitation of public-facing applications, credential theft, malware deployment, persistence mechanisms, and stealthy data exfiltration.</p>



<h3 class="wp-block-heading">Key Objectives</h3>



<ul class="wp-block-list">
<li>Medical research intelligence</li>



<li> Artificial Intelligence research </li>



<li>Defense-related information </li>



<li>Military health research Public health policy data</li>
</ul>



<p>Researchers observed the activity from <strong>September 2023 through November 2025</strong>, indicating a highly patient and well-resourced espionage operation.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="830" src="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-1024x830.png" alt="" class="wp-image-11846" style="aspect-ratio:1.233846489791462;width:606px;height:auto" srcset="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-177x142.png 177w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-300x243.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-768x622.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-1024x830.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1.png 1393w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>High-level attack flow used by UNC6508 to compromise research institutions and steal sensitive information.</p>



<h2 class="wp-block-heading">Initial Access Through REDCap Servers</h2>



<h3 class="wp-block-heading">Why REDCap Was Targeted</h3>



<p>REDCap is extensively used across:</p>



<ul class="wp-block-list">
<li>Hospitals </li>



<li>Clinical research organizations </li>



<li>Universities </li>



<li>Government research programs </li>



<li>Military health institutions</li>
</ul>



<p>Because REDCap stores large volumes of research and patient-related information, it provides an attractive entry point for espionage-focused threat actors.</p>



<p>Researchers observed the attackers probing and exploiting vulnerable or legacy REDCap deployments exposed to the internet. Once access was obtained, they began internal reconnaissance and credential discovery activities.</p>



<h2 class="wp-block-heading">Web Shell Deployment and Persistence</h2>



<p>Following successful compromise, UNC6508 deployed a web shell identified as:</p>



<pre class="wp-block-code"><code>help.php</code></pre>



<p>The web shell served multiple purposes:</p>



<ul class="wp-block-list">
<li>Persistent access </li>



<li>File uploads </li>



<li>Command execution </li>



<li>Further malware deployment</li>
</ul>



<p>This allowed the attackers to maintain long-term access even if passwords were changed or some security controls were implemented.</p>



<h2 class="wp-block-heading">INFINITERED Malware Analysis</h2>



<p>Three months after the initial intrusion, researchers observed deployment of a custom malware family called <strong>INFINITERED</strong>. This malware was specifically engineered to operate inside REDCap environments.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><img decoding="async" width="1024" height="819" src="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-1024x819.png" alt="" class="wp-image-11847" style="aspect-ratio:1.2495632366925407;width:599px;height:auto" srcset="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-177x142.png 177w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-300x240.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-768x615.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-1024x819.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM.png 1402w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Modular architecture of INFINITERED malware used by UNC6508 to maintain persistence, harvest credentials, and execute commands within compromised REDCap environments.</p>



<h2 class="wp-block-heading">Component 1 – Upgrade Interceptor</h2>



<p>The malware monitors REDCap upgrade activities.</p>



<p>When administrators update REDCap, the malware automatically injects itself into newer versions, ensuring persistence across software upgrades</p>



<h2 class="wp-block-heading">Component 2 – Credential Harvester</h2>



<p>This module captures usernames and passwords entered into REDCap login pages.</p>



<p>Stolen credentials are stored within REDCap database tables and later retrieved by attackers.</p>



<h2 class="wp-block-heading">Component 3 – Command-and-Control Backdoor</h2>



<p>The third module acts as a fully functional backdoor.</p>



<p>Researchers found it could:</p>



<ul class="wp-block-list">
<li>Execute shell commands </li>



<li>Upload files </li>



<li>Download files </li>



<li>Run SQL queries</li>
</ul>



<p>Communication was hidden within HTTP cookie values, helping evade traditional detection mechanisms.</p>



<h2 class="wp-block-heading">Abuse of Google Workspace for Data Exfiltration</h2>



<p>One of the most interesting aspects of the campaign was the attackers&#8217; use of legitimate Google Workspace functionality.</p>



<p>After obtaining administrative access, UNC6508 created a content compliance rule named:</p>



<pre class="wp-block-code"><code>Patroit</code></pre>



<p>The rule automatically monitored emails containing specific keywords and forwarded matching messages to attacker-controlled Gmail accounts.</p>



<h2 class="wp-block-heading">Attack Chain Breakdown</h2>



<ul class="wp-block-list">
<li>External Reconnaissance</li>



<li>Initial Compromise</li>



<li>Persistence</li>



<li>Privilege Escalation</li>



<li>Intelligence Gathering</li>
</ul>



<h2 class="wp-block-heading">Potential Impact on Organizations</h2>



<p>Organizations affected by this campaign could experience:</p>



<h3 class="wp-block-heading">Research Theft</h3>



<p>Loss of valuable intellectual property and scientific research.</p>



<h3 class="wp-block-heading">Strategic Intelligence Exposure</h3>



<p>Disclosure of defense and geopolitical information.</p>



<h3 class="wp-block-heading">Credential Compromise</h3>



<p>Unauthorized access to enterprise systems.</p>



<h3 class="wp-block-heading">Regulatory Risks</h3>



<p>Exposure of regulated healthcare and research data.</p>



<h2 class="wp-block-heading">Alternative Indicators of Compromise (IOCs)</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th>IOC Category</th><th>Description</th></tr></thead><tbody><tr><td>Web Shell</td><td>help.php</td></tr><tr><td>Malware Family</td><td>INFINITERED</td></tr><tr><td>Email Rule Name</td><td>Patroit</td></tr><tr><td>Activity</td><td>Unauthorized REDCap upgrades</td></tr><tr><td>Activity</td><td>Suspicious credential harvesting</td></tr><tr><td>Activity</td><td>Unexpected SQL queries</td></tr><tr><td>Activity</td><td>Abnormal Gmail forwarding rules</td></tr><tr><td>Activity</td><td>Unauthorized admin account access</td></tr><tr><td>Activity</td><td>HTTP cookie-based command execution</td></tr><tr><td>Activity</td><td>Unusual database access patterns</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Security Recommendations</h2>



<h3 class="wp-block-heading">Upgrade REDCap Immediately</h3>



<p>Remove legacy versions and apply the latest security updates.</p>



<h3 class="wp-block-heading">Conduct Threat Hunting</h3>



<p>Search for:</p>



<ul class="wp-block-list">
<li>help.php </li>



<li>INFINITERED artifacts </li>



<li>Unauthorized admin activity </li>



<li>Credential harvesting indicators</li>
</ul>



<p>The UNC6508 campaign highlights how modern nation-state threat actors are increasingly targeting research ecosystems to obtain strategic intelligence. By exploiting REDCap servers, deploying INFINITERED malware, and abusing legitimate cloud email features, the attackers maintained access for more than a year while collecting sensitive medical, defense, and technology research data. Organizations operating research platforms should prioritize patching, continuous monitoring, and proactive threat hunting to defend against similar espionage campaigns.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/prc-redcap-medical-espionage/">PRC-Linked Threat Actors Target REDCap Servers to Spy on U.S. Medical Research Organizations</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/prc-redcap-medical-espionage/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Stolen Gemini API Keys Power Automated Telegram Campaign</title>
		<link>https://firsthackersnews.com/stolen-gemini-api-keys/</link>
					<comments>https://firsthackersnews.com/stolen-gemini-api-keys/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 17:41:42 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11782</guid>

					<description><![CDATA[<p>Researchers have uncovered a long-running operation in which a single threat actor used stolen Google Gemini API keys</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/stolen-gemini-api-keys/">Stolen Gemini API Keys Power Automated Telegram Campaign</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Researchers have uncovered a long-running operation in which a single threat actor used stolen Google Gemini API keys and modified AI tools to automate content creation, fraud activities, and online infrastructure management.</p>



<p>The campaign, linked to a Telegram channel with thousands of followers, reportedly used artificial intelligence to generate content, manage online operations, and support cybercriminal activities with very little cost or effort.</p>



<p>The case highlights how AI can be abused to increase the scale and efficiency of malicious online campaigns.</p>



<h2 class="wp-block-heading"><strong>AI Used to Automate Content and Operations</strong></h2>



<p>According to researchers, the attacker found ways to bypass Gemini&#8217;s built-in safety protections through carefully crafted prompts and configuration changes.</p>



<p>Once these restrictions were bypassed, the AI was used for a variety of tasks, including:</p>



<ul class="wp-block-list">
<li>Generating large volumes of content</li>



<li>Automating Telegram posts</li>



<li>Managing stolen API keys</li>



<li>Assisting with infrastructure setup</li>



<li>Supporting online fraud operations</li>
</ul>



<p>Researchers found that the actor relied on dozens of stolen Gemini API keys, allowing continuous access to AI capabilities while avoiding operational costs.</p>



<p>The Telegram channel evolved over time, eventually becoming heavily dependent on AI-generated content designed to engage and influence followers.</p>



<h2 class="wp-block-heading"><strong>From Influence Campaigns to Cybercrime</strong></h2>



<p>Beyond content creation, investigators found evidence that AI was also used to assist with technical tasks often associated with cybercrime.</p>



<p>The AI reportedly helped with:</p>



<ul class="wp-block-list">
<li>Script troubleshooting and development</li>



<li>Cloud service configuration</li>



<li>Infrastructure deployment</li>



<li>Password variation generation</li>



<li>Account compromise activities</li>
</ul>



<p>Researchers linked the operation to several compromised WordPress administrator accounts and at least one cryptocurrency theft incident.</p>



<p>The campaign also promoted a fake cryptocurrency wallet application that allegedly provided attackers with access to victim systems and digital assets.</p>



<h2 class="wp-block-heading"><strong>Growing Concerns Around AI Abuse</strong></h2>



<p>Security experts believe the operation was primarily motivated by financial gain rather than political objectives.</p>



<p>The findings demonstrate how a single individual can now perform activities that previously required larger teams, thanks to automation and AI assistance.</p>



<p>At the same time, the case raises concerns about weaknesses in AI safety controls. Researchers noted that prompt manipulation, persistent jailbreak techniques, and language-based inconsistencies continue to create opportunities for abuse.</p>



<p>The incident serves as another example of how cybercriminals are adapting emerging AI technologies to support fraud, account compromise, and large-scale online influence operations.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/stolen-gemini-api-keys/">Stolen Gemini API Keys Power Automated Telegram Campaign</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/stolen-gemini-api-keys/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Meta AI Flaw Linked to Instagram Password Resets</title>
		<link>https://firsthackersnews.com/meta-ai-vulnerability-instagram/</link>
					<comments>https://firsthackersnews.com/meta-ai-vulnerability-instagram/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 22:10:42 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#AccountTakeover]]></category>
		<category><![CDATA[#AISecurity]]></category>
		<category><![CDATA[#ArtificialIntelligence]]></category>
		<category><![CDATA[#CyberNews]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreats]]></category>
		<category><![CDATA[#datasecurity]]></category>
		<category><![CDATA[#DigitalSecurity]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#Instagram]]></category>
		<category><![CDATA[#InstagramSecurity]]></category>
		<category><![CDATA[#MetaAI]]></category>
		<category><![CDATA[#OnlineSafety]]></category>
		<category><![CDATA[#PasswordReset]]></category>
		<category><![CDATA[#privacy]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#SocialMediaSecurity]]></category>
		<category><![CDATA[#TechnologyNews]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11778</guid>

					<description><![CDATA[<p>A recently disclosed issue involving Meta’s AI-powered support system has raised concerns about the security of Instagram accounts.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/meta-ai-vulnerability-instagram/">Meta AI Flaw Linked to Instagram Password Resets</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A recently disclosed issue involving Meta’s AI-powered support system has raised concerns about the security of Instagram accounts. Researchers claim that attackers were able to abuse the platform’s account recovery process to request password reset codes without properly verifying ownership of the targeted account.</p>



<p>While Meta stated that its infrastructure was not breached, the incident highlights the risks of relying on AI systems for sensitive account management functions.</p>



<h2 class="wp-block-heading">How the Issue Worked</h2>



<p>The problem was reportedly linked to the logic used by Meta&#8217;s AI support assistant. Instead of exploiting servers or software vulnerabilities, attackers allegedly manipulated the chatbot into triggering password recovery actions.</p>



<p>According to researchers, the AI system could be persuaded to send password reset links or codes without performing sufficient identity checks. In some cases, simply knowing a target&#8217;s Instagram username may have been enough to initiate the process.</p>



<p>This type of attack is different from traditional hacking methods because it focuses on exploiting the behavior of automated systems rather than technical flaws in infrastructure.</p>



<p>Researchers noted that the issue demonstrated how AI tools can become vulnerable when strict authentication controls and security safeguards are not fully enforced.</p>



<h2 class="wp-block-heading">Valuable Instagram Accounts Were Targeted</h2>



<p>Reports indicate that attackers focused primarily on high-value Instagram usernames and accounts that are often traded in underground marketplaces.</p>



<p>Short, rare, and highly desirable usernames can sell for significant amounts of money, making them attractive targets for cybercriminals.</p>



<p>Security researchers found evidence suggesting that compromised accounts were quickly offered for sale through private online channels, highlighting the growing business of account takeover operations.</p>



<p>This trend reflects an evolving cybercrime ecosystem where attackers target digital identities that can be rapidly monetized.</p>



<h2 class="wp-block-heading">Meta Responds and Fixes the Issue</h2>



<p>Meta has confirmed that the problem has been addressed and stated that user accounts remain secure.</p>



<p>According to the company, the issue allowed certain password reset requests to be triggered improperly, but there was no compromise of Meta&#8217;s backend systems or customer databases.</p>



<p>The company quickly implemented a fix after receiving reports from researchers and emphasized that the vulnerability has been resolved.</p>



<h2 class="wp-block-heading">Lessons for Users and Platforms</h2>



<p>The incident serves as a reminder that AI-powered support tools can introduce new security challenges if they are not carefully designed.</p>



<p>To reduce risk, organizations should implement:</p>



<ul class="wp-block-list">
<li>Strong identity verification controls</li>



<li>Strict rate-limiting mechanisms</li>



<li>Context-aware AI decision making</li>



<li>Enhanced monitoring for abuse attempts</li>



<li>Additional safeguards for account recovery processes</li>
</ul>



<p>Researchers also noted that accounts protected with two-factor authentication (2FA) were not affected by the reported attacks.</p>



<p>As AI becomes more integrated into customer support and account management systems, security experts expect attackers to continue testing these technologies for weaknesses. Strong authentication and layered security controls remain essential for protecting user accounts from emerging threats.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/meta-ai-vulnerability-instagram/">Meta AI Flaw Linked to Instagram Password Resets</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/meta-ai-vulnerability-instagram/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Denies Lawsuit Threats Against Researchers</title>
		<link>https://firsthackersnews.com/microsoft-security-researchers-clarification/</link>
					<comments>https://firsthackersnews.com/microsoft-security-researchers-clarification/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 21:46:16 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11774</guid>

					<description><![CDATA[<p>Microsoft has publicly stated that it does not plan to take legal action against security researchers who responsibly</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-security-researchers-clarification/">Microsoft Denies Lawsuit Threats Against Researchers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft has publicly stated that it does not plan to take legal action against security researchers who responsibly discover and share vulnerabilities.</p>



<p>The statement comes after criticism from the cybersecurity community following a dispute involving a researcher known as &#8220;Nightmare-Eclipse.&#8221; Many researchers were concerned that Microsoft&#8217;s earlier comments could discourage independent security research and vulnerability disclosure.</p>



<p>The company has now clarified that its focus is on individuals who intentionally cause harm, not those conducting legitimate security research.</p>



<h2 class="wp-block-heading"><strong>Dispute Sparked by Public Vulnerability Disclosures</strong></h2>



<p>The controversy began when Nightmare-Eclipse started releasing details of several previously unpatched Windows vulnerabilities, along with proof-of-concept exploit code.</p>



<p>The disclosed flaws affected important Windows security features, including Microsoft Defender and BitLocker. Some of the vulnerabilities were later confirmed to be actively exploited in real-world attacks.</p>



<p>According to the researcher, the public disclosures were driven by frustration over previous interactions with Microsoft&#8217;s vulnerability reporting process. The researcher claimed that access to Microsoft&#8217;s reporting platform had been removed and that submitted findings were not handled appropriately.</p>



<p>Microsoft later criticized the public release of unpatched vulnerabilities and stated that such disclosures could place customers at risk. The company&#8217;s comments also referenced potential legal action against individuals involved in harmful activities, which triggered widespread debate across the cybersecurity community.</p>



<h2 class="wp-block-heading"><strong>Microsoft Reassures the Security Community</strong></h2>



<p>Following the backlash, Microsoft issued a new statement to clarify its position.</p>



<p>The company emphasized that it supports security research and has no intention of pursuing legal action against researchers who identify and disclose vulnerabilities. Microsoft said legal measures would only be considered in cases involving unlawful actions that cause actual harm to customers.</p>



<p>The company also acknowledged that some interactions with researchers may not have met expectations and expressed its commitment to improving communication and collaboration.</p>



<p>Microsoft reaffirmed its support for Coordinated Vulnerability Disclosure (CVD), encouraging researchers to report vulnerabilities through official channels before making findings public.</p>



<h2 class="wp-block-heading"><strong>Importance of Researcher-Vendor Collaboration</strong></h2>



<p>The incident highlights the delicate relationship between technology vendors and the security research community.</p>



<p>Security researchers play a critical role in identifying weaknesses before cybercriminals can exploit them. At the same time, vendors rely on responsible disclosure processes to develop patches and protect users.</p>



<p>Microsoft stated that it continues to welcome vulnerability reports through its public reporting portal and remains committed to working with researchers regardless of previous interactions.</p>



<p>The situation serves as a reminder that effective communication and cooperation between vendors and researchers are essential for improving cybersecurity and protecting users worldwide.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-security-researchers-clarification/">Microsoft Denies Lawsuit Threats Against Researchers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-security-researchers-clarification/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Chat Data Found Stored Without Encryption</title>
		<link>https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/</link>
					<comments>https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 25 May 2026 17:41:58 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[MacOS]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[#AppleSecurity]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreat]]></category>
		<category><![CDATA[#DataProtection]]></category>
		<category><![CDATA[#Encryption]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#iOSSecurity]]></category>
		<category><![CDATA[#macOSSecurity]]></category>
		<category><![CDATA[#Meta]]></category>
		<category><![CDATA[#MobileSecurity]]></category>
		<category><![CDATA[#privacy]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#WhatsApp]]></category>
		<category><![CDATA[#WhatsAppSecurity]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11745</guid>

					<description><![CDATA[<p>Security researchers have raised concerns about how WhatsApp stores chat data on macOS and iOS devices. According to</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/">WhatsApp Chat Data Found Stored Without Encryption</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have raised concerns about how WhatsApp stores chat data on macOS and iOS devices. According to recent findings, message databases may be stored in plaintext inside shared app group containers, potentially exposing sensitive conversations under certain conditions.</p>



<p>Researchers from Mysk reported that WhatsApp uses a shared container linked to Meta applications, identified as <code>group.com.facebook.family</code>. On Apple devices, app group containers allow applications from the same developer to share data and resources.</p>



<p>Because Facebook, Instagram, and WhatsApp belong to the same ecosystem, the shared architecture could introduce privacy and security concerns if exploited alongside operating system vulnerabilities.</p>



<h2 class="wp-block-heading"><strong>Shared Containers Raise Privacy Concerns</strong></h2>



<p>The researchers found that WhatsApp chat databases stored inside these containers are not encrypted at rest. This means the data may remain readable if attackers gain access to the device or exploit weaknesses in the operating system.</p>



<p>According to the report, the following risks were identified:</p>



<ul class="wp-block-list">
<li>Chat histories may be stored in plaintext</li>



<li>Other Meta-owned apps could theoretically access shared data</li>



<li>Users receive no alerts when such access occurs</li>



<li>The issue affects both macOS and iOS environments</li>
</ul>



<p>Researchers also demonstrated that WhatsApp chat histories could be extracted from iPhone backups, where the same unencrypted storage structure was observed.</p>



<p>The findings highlight an important distinction in security design. While WhatsApp uses end-to-end encryption to protect messages during transmission, that protection does not automatically secure data stored locally on the device.</p>



<h2 class="wp-block-heading"><strong>macOS Vulnerability Increases Exposure Risk</strong></h2>



<p>The risk becomes more serious when combined with a recently disclosed macOS vulnerability tracked as CVE-2026-28910. The flaw affected Apple’s Archive Utility tool and reportedly allowed attackers to bypass App Sandbox protections.</p>



<p>By abusing this vulnerability, attackers could potentially:</p>



<ul class="wp-block-list">
<li>Access protected application containers</li>



<li>Extract sensitive information from apps</li>



<li>Bypass Apple’s Transparency, Consent, and Control protections</li>



<li>Access chat histories from applications like WhatsApp</li>
</ul>



<p>Researchers presented a proof-of-concept demonstration showing how the vulnerability could be combined with WhatsApp’s storage behavior to retrieve chat data.</p>



<h2 class="wp-block-heading"><strong>Security Debate Around the Findings</strong></h2>



<p>Not all experts agree on the severity of the issue. WABetaInfo stated that although the databases may not be encrypted locally, Apple’s sandboxing system still provides strong isolation between applications.</p>



<p>From this perspective, attackers would still require elevated system privileges or a separate operating system exploit to access the stored data.</p>



<p>However, researchers at Mysk argue that shared app group permissions between Meta applications reduce isolation boundaries and increase the potential attack surface.</p>



<p>The discussion highlights broader concerns about local data protection in modern mobile ecosystems, especially when multiple applications share common storage environments.</p>



<h2 class="wp-block-heading"><strong>Recommendations for Users</strong></h2>



<p>Security experts recommend several steps to reduce potential exposure risks:</p>



<ul class="wp-block-list">
<li>Enable encrypted Finder or iTunes backups</li>



<li>Keep macOS and iOS updated with the latest security patches</li>



<li>Use strong device passcodes and device encryption</li>



<li>Limit unnecessary applications from the same developer ecosystem</li>



<li>Regularly review application permissions and backup settings</li>
</ul>



<p>At the time of reporting, there were no confirmed cases of widespread exploitation linked to the findings. However, the research highlights the importance of protecting sensitive data not only during transmission but also while stored on devices.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/">WhatsApp Chat Data Found Stored Without Encryption</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Gamaredon Phishing Attacks Use GammaDrop Malware</title>
		<link>https://firsthackersnews.com/gamaredon-phishing-attacks/</link>
					<comments>https://firsthackersnews.com/gamaredon-phishing-attacks/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 18 May 2026 14:13:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberEspionage]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EthicalHacking]]></category>
		<category><![CDATA[#gamaredon]]></category>
		<category><![CDATA[#gammadrop]]></category>
		<category><![CDATA[#gammaload]]></category>
		<category><![CDATA[#governmentsecurity]]></category>
		<category><![CDATA[#Hacking]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#ITSecurity]]></category>
		<category><![CDATA[#Malware]]></category>
		<category><![CDATA[#malwareloader]]></category>
		<category><![CDATA[#phishingattacks]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#spearphishing]]></category>
		<category><![CDATA[#ThreatHunting]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#vbscriptmalware]]></category>
		<category><![CDATA[#winrarvulnerability]]></category>
		<category><![CDATA[#ZeroTrust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11713</guid>

					<description><![CDATA[<p>A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government organizations through large-scale</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gamaredon-phishing-attacks/">Gamaredon Phishing Attacks Use GammaDrop Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government organizations through large-scale phishing attacks and multi-stage malware delivery chains. The operation combines social engineering, abuse of trusted infrastructure, and custom malware loaders to maintain long-term access to compromised systems.</p>



<p>Also tracked as UAC-0010 or Shuckworm, Gamaredon continues to exploit CVE-2025-8088, a directory traversal vulnerability in WinRAR that allows malicious files to be written outside the intended extraction directory. Although the flaw has been widely abused since 2025, researchers noted that Gamaredon’s campaigns stand out due to their persistence, rapid infrastructure rotation, and repeated targeting of Ukrainian government entities.</p>



<h2 class="wp-block-heading">Phishing Campaign Delivers GammaDrop Malware</h2>



<p>The attacks begin with carefully crafted spearphishing emails sent either from compromised Ukrainian government accounts or spoofed domains designed to appear legitimate. Many of these emails mimic official court summons, legal notices, or government-related communications to increase the likelihood of user interaction.</p>



<p>The phishing attachments typically contain malicious RAR or ARJ archives disguised as regular documents. Inside the archive, researchers identified:</p>



<ul class="wp-block-list">
<li>A decoy PDF document used to distract the victim</li>



<li>A hidden VBScript payload stored using NTFS Alternate Data Streams (ADS)</li>
</ul>



<p>When the archive is extracted, the WinRAR vulnerability is abused to silently place the malicious VBScript into the Windows Startup folder. This ensures persistence on the infected machine without requiring additional user interaction.</p>



<p>The first-stage payload, known as GammaDrop, functions as a downloader responsible for retrieving additional malware from attacker-controlled infrastructure. Researchers observed that the script is heavily obfuscated using randomized variables, junk code, and automated generation techniques commonly associated with Gamaredon operations.</p>



<h2 class="wp-block-heading">GammaLoad Expands Persistence and Reconnaissance</h2>



<p>After execution, GammaDrop downloads a second-stage malware component called GammaLoad from infrastructure hosted through Cloudflare Workers. The payload is delivered as an HTA file and launched using mshta.exe in a hidden window to avoid drawing attention.</p>



<p>GammaLoad acts as both a persistence mechanism and a reconnaissance tool. It creates RunOnce registry entries and continuously communicates with command-and-control servers to receive instructions and additional payloads.</p>



<p>The malware collects system-level information including:</p>



<ul class="wp-block-list">
<li>Computer name</li>



<li>System drive details</li>



<li>Volume serial numbers</li>



<li>Victim identification data</li>
</ul>



<p>This information is embedded into beaconing traffic, allowing attackers to uniquely track infected systems and selectively deliver follow-up malware.</p>



<p>Researchers also observed that Gamaredon frequently rotates its infrastructure using fast-flux DNS, dynamic DNS services, and short-lived domains to evade detection. Communication traffic is disguised using legitimate browser user-agent strings, while some newer variants imitate automated services such as Bingbot to blend malicious traffic with normal network activity.</p>



<p>The Security Service of Ukraine (SSU), along with regional government and law enforcement organizations, remains one of the primary targets of these campaigns. Researchers believe the operation’s success is also supported by weak email authentication practices across some targeted domains, where missing or poorly configured SPF, DKIM, and DMARC policies allow attackers to spoof trusted senders more effectively.</p>



<p>Although the malware itself is not considered highly advanced, Gamaredon continues to maintain a strong operational presence through continuous adaptation, large-scale phishing activity, and aggressive infrastructure management.</p>



<p><strong>Security teams are advised to patch vulnerable WinRAR installations immediately, strengthen email authentication controls, monitor suspicious archive-based phishing activity, and block known malicious infrastructure associated with the campaign.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gamaredon-phishing-attacks/">Gamaredon Phishing Attacks Use GammaDrop Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/gamaredon-phishing-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Teams Boosts Performance on Low-End Devices</title>
		<link>https://firsthackersnews.com/microsoft-teams-efficiency-mode/</link>
					<comments>https://firsthackersnews.com/microsoft-teams-efficiency-mode/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 23 Apr 2026 19:48:20 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[#CollaborationTools]]></category>
		<category><![CDATA[#DigitalWorkplace]]></category>
		<category><![CDATA[#EfficiencyMode]]></category>
		<category><![CDATA[#MicrosoftTeams]]></category>
		<category><![CDATA[#PerformanceOptimization]]></category>
		<category><![CDATA[#Productivity]]></category>
		<category><![CDATA[#SoftwareUpdate]]></category>
		<category><![CDATA[#TeamsUpdate]]></category>
		<category><![CDATA[#TechNews]]></category>
		<category><![CDATA[#WorkplaceTech]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11631</guid>

					<description><![CDATA[<p>Microsoft is rolling out a new feature called Efficiency Mode in Microsoft Teams to improve performance, especially on</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-teams-efficiency-mode/">Microsoft Teams Boosts Performance on Low-End Devices</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft is rolling out a new feature called Efficiency Mode in Microsoft Teams to improve performance, especially on devices with limited hardware resources.</p>



<p>Many users experience slow performance during meetings or while switching between chats, particularly on older laptops or systems with low memory. This new mode is designed to solve that problem by making Teams smarter about how it uses system resources. The rollout is expected to begin in early May 2026 and will gradually reach users worldwide by mid-May.</p>



<p>Instead of applying the same performance settings to every device, Teams will now adapt based on the hardware it is running on. This means users with lower-end devices can still have a smooth experience without needing upgrades.</p>



<h2 class="wp-block-heading"><strong>How Efficiency Mode Works</strong></h2>



<p>When Efficiency Mode is active, Teams automatically adjusts its behavior to reduce strain on the system. These changes happen in the background without requiring user input.</p>



<p>Some of the key improvements include:</p>



<ul class="wp-block-list">
<li>Video quality is dynamically lowered during meetings to reduce CPU and bandwidth usage while still maintaining clear communication</li>



<li>The app launches faster by avoiding heavy initial loading, showing a simpler interface instead of opening a chat window immediately</li>



<li>Background processes are minimized to prevent unnecessary memory and CPU consumption</li>



<li>A visual indicator appears in the app so users know when Efficiency Mode is active</li>
</ul>



<p>These adjustments help reduce lag, improve responsiveness, and make meetings more stable, especially when multiple apps are running at the same time.</p>



<h2 class="wp-block-heading"><strong>Automatic Enablement and User Control</strong></h2>



<p>Efficiency Mode is automatically enabled on devices that are likely to benefit from it. This ensures users get better performance without needing to change any settings.</p>



<p>However, Microsoft also gives users full control. If someone prefers the standard experience with full visuals and higher resource usage, they can disable Efficiency Mode in the settings. This flexibility allows users to choose between performance and full feature usage based on their needs.</p>



<p>Importantly, Microsoft has confirmed that this feature does not affect compliance, privacy, or security settings, making it safe for both personal and enterprise use.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>



<h2 class="wp-block-heading"><strong>What IT Teams Should Know</strong></h2>



<p>For organizations, this update is relatively simple to manage. Since the feature is enabled automatically, most environments will not require configuration changes.</p>



<p>Still, IT teams should be aware of a few key points:</p>



<ul class="wp-block-list">
<li>Helpdesk teams should understand how the feature works to assist users with questions</li>



<li>Employees may need guidance on how to turn the feature on or off</li>



<li>Internal documentation may need updates to reflect the new behavior of Teams</li>



<li>Monitoring user feedback can help determine if the feature improves productivity</li>
</ul>



<p>By preparing ahead, organizations can ensure a smooth transition and better user experience.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>Efficiency Mode is an important step in making Teams more accessible and reliable across different types of devices. Not all users have high-performance systems, and performance issues can disrupt communication and collaboration.</p>



<p>By optimizing how Teams uses CPU, memory, and network resources, Microsoft is improving usability without removing core features. This means more users can participate in meetings, collaborate effectively, and stay productive regardless of their device limitations.</p>



<p>In the long run, features like this help reduce the gap between high-end and low-end devices, making modern workplace tools more inclusive and efficient.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-teams-efficiency-mode/">Microsoft Teams Boosts Performance on Low-End Devices</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-teams-efficiency-mode/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
