<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Thu, 27 Aug 2026 17:15:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>TP-Link Kasa Flaw Could Disrupt Smart Devices</title>
		<link>https://firsthackersnews.com/tp-link-kasa-vulnerability/</link>
					<comments>https://firsthackersnews.com/tp-link-kasa-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 17:14:57 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IoT Security]]></category>
		<category><![CDATA[Kasa]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Smart Home Security]]></category>
		<category><![CDATA[tp-link]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12297</guid>

					<description><![CDATA[<p>TP-Link has warned about a high-severity security vulnerability affecting several Kasa smart plugs, switches, and other smart home</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/tp-link-kasa-vulnerability/">TP-Link Kasa Flaw Could Disrupt Smart Devices</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>TP-Link has warned about a <strong>high-severity security vulnerability</strong> affecting several Kasa smart plugs, switches, and other smart home products.</p>



<p>Tracked as <strong>CVE-2026-76784</strong>, the flaw could allow an attacker on the same local network to send unauthorized commands to vulnerable devices. The issue has a <strong>CVSS v4.0 score of 8.7</strong>.</p>



<p>The vulnerability is caused by weaknesses in the security used to protect communication between Kasa devices and their local control components.</p>



<h2 class="wp-block-heading"><strong>Attackers Could Manipulate Device Commands</strong></h2>



<p>An attacker does not need an account or special permissions to exploit the issue. However, they must have access to the <strong>same local network or wireless environment</strong> as the targeted device.</p>



<p>This could make shared Wi-Fi networks, compromised home networks, and poorly separated business networks potential attack environments.</p>



<p>Attackers could potentially capture legitimate device commands and reuse them or create their own commands.</p>



<p>Depending on the device, this could allow someone to:</p>



<ul class="wp-block-list">
<li>Turn smart plugs, switches, or lights on or off</li>



<li>Interrupt connected appliances</li>



<li>Change device behavior or schedules</li>



<li>Repeatedly send commands and disrupt normal operation</li>
</ul>



<p>The affected products include several Kasa smart plugs, switches, and the <strong>KL125 smart bulb</strong>, along with other models.</p>



<h2 class="wp-block-heading"><strong>Firmware Updates Are Available</strong></h2>



<p>TP-Link has released updated firmware for affected products. Because firmware versions depend on the <strong>specific model, hardware revision, and region</strong>, users should check their exact device before installing an update.</p>



<p>Users can look for the latest firmware through the <strong>TP-Link Download Center or Kasa Smart app</strong>.</p>



<p>Until devices are updated, users and organizations can reduce their exposure by:</p>



<ul class="wp-block-list">
<li>Placing IoT devices on a separate network or VLAN</li>



<li>Keeping smart devices away from sensitive systems</li>



<li>Limiting access from guest networks</li>



<li>Watching for unexpected device activity</li>
</ul>



<p>The vulnerability is a reminder that smart home devices do not need to be directly exposed to the internet to become a security concern. <strong>An attacker who gains access to the local network may still be able to manipulate vulnerable IoT devices.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/tp-link-kasa-vulnerability/">TP-Link Kasa Flaw Could Disrupt Smart Devices</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/tp-link-kasa-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GitLab AI Agent Flaw Could Expose CI Pipelines</title>
		<link>https://firsthackersnews.com/gitlab-duo-claude-vulnerability/</link>
					<comments>https://firsthackersnews.com/gitlab-duo-claude-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 16:59:20 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CI pipeline security]]></category>
		<category><![CDATA[Duo Claude AI agent]]></category>
		<category><![CDATA[GitLab CVE-2026-18252]]></category>
		<category><![CDATA[GitLab security flaw]]></category>
		<category><![CDATA[GitLab vulnerability]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12294</guid>

					<description><![CDATA[<p>GitLab has released security updates for a high-severity vulnerability in its Duo Claude AI agent that could allow</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gitlab-duo-claude-vulnerability/">GitLab AI Agent Flaw Could Expose CI Pipelines</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>GitLab has released security updates for a <strong>high-severity vulnerability in its Duo Claude AI agent</strong> that could allow authenticated developers to run unauthorized commands inside CI pipeline environments.</p>



<p>Tracked as <strong>CVE-2026-18252</strong>, the flaw has a <strong>CVSS score of 7.3</strong> and affects GitLab Enterprise Edition. GitLab fixed the issue in versions <strong>19.3.1, 19.2.5, and 19.1.7</strong>.</p>



<p>GitLab.com has already been updated, but organizations running self-managed installations should upgrade as soon as possible.</p>



<h2 class="wp-block-heading">How the Vulnerability Works</h2>



<p>The problem is linked to the way the Duo Claude AI agent processes configuration supplied from a user-controlled source.</p>



<p>Under certain conditions, an authenticated user with <strong>Developer-level permissions</strong> could manipulate this behavior and cause the AI agent to execute arbitrary commands within a CI environment.</p>



<p>This is particularly concerning because CI pipelines often have access to sensitive development resources, including:</p>



<ul class="wp-block-list">
<li>Source code and build files</li>



<li>Deployment credentials and cloud tokens</li>



<li>Package registry credentials</li>



<li>Secrets used by automated jobs</li>
</ul>



<p>An attacker who gains command execution could potentially access exposed secrets, modify build artifacts, or interfere with software development and deployment processes.</p>



<h2 class="wp-block-heading">GitLab Releases Security Fix</h2>



<p>GitLab classified the vulnerability as an <strong>untrusted control sphere</strong> issue. Exploitation requires network access, low-level privileges, and user interaction.</p>



<p>There is currently no public exploit or evidence that the vulnerability is being actively exploited.</p>



<p>The same GitLab patch releases also address several other security issues, including denial-of-service vulnerabilities, access-control problems, and weaknesses involving pipeline and compliance policies.</p>



<p>Self-managed administrators should upgrade to the appropriate patched release:</p>



<ul class="wp-block-list">
<li><strong>GitLab 19.3.1</strong></li>



<li><strong>GitLab 19.2.5</strong></li>



<li><strong>GitLab 19.1.7</strong></li>
</ul>



<p>The updates may require database migrations, so administrators should plan the upgrade according to their deployment architecture.</p>



<p>The vulnerability also highlights a broader security concern: <strong>AI agents integrated into development platforms should be treated as powerful automation systems with access to code and secrets.</strong></p>



<p>Organizations should restrict access to AI-agent configurations, limit CI secrets, isolate pipeline jobs, and monitor automated workflows for unexpected command execution.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gitlab-duo-claude-vulnerability/">GitLab AI Agent Flaw Could Expose CI Pipelines</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/gitlab-duo-claude-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Patch Now: Critical Next.js Flaw Enables RCE</title>
		<link>https://firsthackersnews.com/nextjs-vulnerabilities-remote-code-execution/</link>
					<comments>https://firsthackersnews.com/nextjs-vulnerabilities-remote-code-execution/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 16:45:39 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Next.js RCE]]></category>
		<category><![CDATA[Next.js security flaw]]></category>
		<category><![CDATA[Next.js vulnerability]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[vulnerability impact]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12291</guid>

					<description><![CDATA[<p>Two critical security issues in Next.js could allow attackers to execute code remotely on vulnerable applications without logging</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/nextjs-vulnerabilities-remote-code-execution/">Patch Now: Critical Next.js Flaw Enables RCE</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Two critical security issues in <strong>Next.js</strong> could allow attackers to execute code remotely on vulnerable applications without logging in.</p>



<p>The first vulnerability, <strong>CVE-2026-75604</strong>, affects applications using the Image Optimization API on Windows servers. It is related to improper handling of file paths and can allow attackers to access files outside the intended application directory.</p>



<p>The issue affects certain Next.js versions using either the <strong>Pages Router or App Router</strong>, particularly when running on Windows-based systems.</p>



<h2 class="wp-block-heading">Windows Applications Face Path Traversal Risk</h2>



<p>The vulnerability is caused by insufficient restrictions on attacker-controlled file paths. By sending a specially crafted request, an attacker could potentially make the application access unintended locations on the server.</p>



<p>Successful exploitation could result in:</p>



<ul class="wp-block-list">
<li>Exposure of sensitive files</li>



<li>Unauthorized modification of server content</li>



<li>Disruption of application availability</li>
</ul>



<p>The flaw requires no authentication or user interaction, although the advisory rates exploitation complexity as high.</p>



<p>Vercel has addressed the issue in <strong>Next.js 15.5.24 and 16.3.3</strong>. There is no reliable workaround for affected Windows deployments, making an update the recommended solution.</p>



<h2 class="wp-block-heading">Malicious AVIF Images Could Trigger RCE</h2>



<p>The second critical issue affects applications using the <strong>Image Optimization API</strong> to process AVIF images.</p>



<p>The problem is linked to <strong>libheif</strong>, an image-processing component used through the Sharp package. An attacker could submit a specially crafted AVIF image to a vulnerable image optimization endpoint.</p>



<p>If the malicious file is processed by the affected component, it could potentially lead to <strong>remote code execution on the server</strong>.</p>



<p>The vulnerability affects a wide range of Next.js releases, with fixes available in <strong>15.5.24 and 16.3.3</strong>.</p>



<p>Next.js temporarily disabled AVIF optimization as a protective measure while the dependency issue was being addressed, but organizations should still upgrade their applications rather than relying on this mitigation.</p>



<h2 class="wp-block-heading">Update Next.js Deployments</h2>



<p>Organizations using Next.js should update to a patched release and rebuild their production applications or containers.</p>



<p>Security teams should also review:</p>



<ul class="wp-block-list">
<li>Public image-upload and image-optimization endpoints</li>



<li>Windows-hosted Next.js applications</li>



<li>Logs for unusual file-path requests</li>



<li>Suspicious AVIF image-processing activity</li>
</ul>



<p>Keeping both <strong>Next.js and its underlying dependencies</strong> updated is important because vulnerabilities in supporting libraries can also create serious risks for applications built on the framework.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/nextjs-vulnerabilities-remote-code-execution/">Patch Now: Critical Next.js Flaw Enables RCE</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/nextjs-vulnerabilities-remote-code-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WordPress Plugin Flaw Puts 400,000 Sites at Risk</title>
		<link>https://firsthackersnews.com/wordpress-plugin-flaw-puts-400000-sites-at-risk/</link>
					<comments>https://firsthackersnews.com/wordpress-plugin-flaw-puts-400000-sites-at-risk/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 21:08:52 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[account takeover]]></category>
		<category><![CDATA[CVE-2026-19632]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[TranslatePress]]></category>
		<category><![CDATA[WordPress Security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12287</guid>

					<description><![CDATA[<p>A critical security flaw in the TranslatePress WordPress plugin could allow attackers to take control of administrator accounts</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/wordpress-plugin-flaw-puts-400000-sites-at-risk/">WordPress Plugin Flaw Puts 400,000 Sites at Risk</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A critical security flaw in the <strong>TranslatePress WordPress plugin</strong> could allow attackers to take control of administrator accounts without needing to log in first.</p>



<p>Tracked as <strong>CVE-2026-19632</strong>, the vulnerability affects TranslatePress versions up to <strong>3.3.1</strong>. The plugin has more than 400,000 active installations, making the issue important for a large number of WordPress websites.</p>



<p>The vulnerability has a <strong>CVSS score of 9.8</strong>, placing it in the critical category. It has been fixed in <strong>TranslatePress 3.3.2</strong>.</p>



<h2 class="wp-block-heading">How the Vulnerability Can Be Exploited</h2>



<p>The problem is related to how TranslatePress handles password-reset emails and stores text that can be translated.</p>



<p>Under certain settings, a password-reset link generated for an administrator can accidentally be saved inside the plugin&#8217;s translation data. This link contains information that could allow someone to reset the administrator&#8217;s password.</p>



<p>The affected translation data can then be accessed through a publicly available AJAX function in the plugin.</p>



<p>An attacker who knows an administrator&#8217;s username or email address could potentially:</p>



<ul class="wp-block-list">
<li>Request a password reset</li>



<li>Find the exposed reset link</li>



<li>Set a new administrator password</li>



<li>Log in and take control of the website</li>
</ul>



<h2 class="wp-block-heading">Administrator Access Can Lead to Full Takeover</h2>



<p>Successful exploitation could give an attacker administrator-level access to the affected WordPress site.</p>



<p>Once inside, an attacker could install malicious plugins, modify themes, create additional administrator accounts, change website content, or access sensitive information.</p>



<p>The vulnerability does not affect every TranslatePress installation under the same conditions. The exposure depends on how the administrator&#8217;s language settings and the plugin&#8217;s translation features are configured.</p>



<p>The issue was responsibly reported to Wordfence, which worked with TranslatePress developer Cozmoslabs to address the problem. A security update was released on <strong>August 13, 2026</strong>.</p>



<h2 class="wp-block-heading">Update TranslatePress Immediately</h2>



<p>Website owners using TranslatePress should update to <strong>version 3.3.2 or later</strong> as soon as possible.</p>



<p>Administrators should also review their websites for unexpected changes, unfamiliar user accounts, or newly installed plugins and themes. Enabling <strong>two-factor authentication or passkeys</strong> can provide another layer of protection for administrator accounts.</p>



<p>Keeping WordPress plugins updated is especially important because a vulnerable plugin can become an entry point to the entire website.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/wordpress-plugin-flaw-puts-400000-sites-at-risk/">WordPress Plugin Flaw Puts 400,000 Sites at Risk</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/wordpress-plugin-flaw-puts-400000-sites-at-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>npm Packages Exploited for ClickFix Phishing</title>
		<link>https://firsthackersnews.com/malicious-npm-packages-clickfix-phishing/</link>
					<comments>https://firsthackersnews.com/malicious-npm-packages-clickfix-phishing/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 16:46:11 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[ClickFix phishing]]></category>
		<category><![CDATA[npm packages]]></category>
		<category><![CDATA[npm security]]></category>
		<category><![CDATA[package mirror abuse]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12281</guid>

					<description><![CDATA[<p>Security researchers have uncovered a campaign involving 24 malicious npm packages that use legitimate package-mirroring services to deliver</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/malicious-npm-packages-clickfix-phishing/">npm Packages Exploited for ClickFix Phishing</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have uncovered a campaign involving <strong>24 malicious npm packages</strong> that use legitimate package-mirroring services to deliver phishing content.</p>



<p>The attackers are not primarily interested in getting developers to install the packages. Instead, they are using the packages as a place to store deceptive web pages. Because those pages can be accessed through well-known package-hosting domains, the links may appear more trustworthy to unsuspecting users.</p>



<p>The campaign was discovered by OX Security, which found that the affected packages contained similar HTML-based phishing content. Some of the packages were receiving hundreds of downloads each week before they were taken down.</p>



<h2 class="wp-block-heading"><strong>Trusted Domains Used to Build Trust</strong></h2>



<p>The malicious packages include HTML files designed to resemble familiar security verification pages, including fake Cloudflare CAPTCHA screens.</p>



<p>When someone opens one of these files through a package mirror, hidden JavaScript can communicate with external infrastructure controlled by the attackers. The visitor can then be sent to another website chosen by the attackers.</p>



<p>This approach gives criminals an advantage: the initial link may point to a <strong>legitimate package-mirror domain</strong> rather than a newly created suspicious website.</p>



<p>Services such as unpkg and other npm mirrors are commonly used by developers, making them difficult to block across an organization.</p>



<p>The destination can also be changed later, meaning the same hosted file could potentially be used to send visitors to different phishing campaigns.</p>



<h2 class="wp-block-heading"><strong>ClickFix Makes the Attack More Dangerous</strong></h2>



<p>The campaign is particularly concerning because it can be connected to the growing <strong>ClickFix</strong> attack technique.</p>



<p>ClickFix campaigns typically show victims a fake verification message and instruct them to perform an action, such as copying a command and running it on their computer. Instead of exploiting a technical vulnerability, the attacker relies on the victim to complete the dangerous step.</p>



<p>Security teams should therefore watch for unusual activity involving package mirrors, especially when employees are accessing HTML files directly rather than downloading normal development dependencies.</p>



<p>Developers should also be careful with package links received through emails, messages, tickets, or search results. A familiar domain does not guarantee that every file hosted on it is safe.</p>



<p>Most importantly, <strong>never run a command simply because a webpage claims it is required to complete a CAPTCHA, security check, or verification process.</strong></p>



<p>This campaign demonstrates how attackers are finding creative ways to hide phishing infrastructure inside services that organizations already trust.</p>



<p><strong>Indicators of compromise (IoCs):-</strong><a href="https://cybersecuritynews.com/fake-npm-install-messages-hide-rat-malware/" target="_blank" rel="noreferrer noopener"></a></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>Domain</td><td><code>login[.]microsofte[.]live</code></td><td>Typosquatted Microsoft domain used by the earlier campaign version</td></tr><tr><td>Domain</td><td><code>api[.]keyval[.]org</code></td><td>Legitimate key-value service abused to retrieve encrypted redirect data</td></tr><tr><td>URL</td><td><code>https://unpkg[.]com/ndmxchdjxn2@1.0.0/index.html</code></td><td>Direct mirror-hosted malicious HTML page</td></tr><tr><td>Encoded value</td><td><code>PpihAtpV1i29jeS3Skk7XU74X2Zkd5wyzF2DOzY77k1Fz7GNvGafkxVGs+z6VOGy6E43n+JQgKSUsn+S5NjXlBmcq4=</code></td><td>Encrypted value retrieved through the remote logic</td></tr><tr><td>Malicious npm package</td><td><code>bgzxcuite2</code></td><td>Microsoft typosquat family, taken down</td></tr><tr><td>Malicious npm package</td><td><code>prezdentkxheiw</code></td><td>Microsoft typosquat family, taken down</td></tr><tr><td>Malicious npm package</td><td><code>egair0810</code></td><td>Microsoft typosquat family, taken down</td></tr><tr><td>Malicious npm package</td><td><code>mnteckets</code></td><td>Microsoft typosquat family, taken down</td></tr><tr><td>Malicious npm package</td><td><code>airdzticket</code></td><td>Microsoft typosquat family, taken down</td></tr><tr><td>Malicious npm package</td><td><code>egypt0811</code></td><td>Microsoft typosquat family, taken down</td></tr><tr><td>Malicious npm package</td><td><code>passport811</code></td><td>Microsoft typosquat family, taken down</td></tr><tr><td>Malicious npm package</td><td><code>vxhjkseuiaqkb</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>ndmushdkeqe</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>ndmxchdjxn2</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>ndmfguyhoxc3</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>mjsdqwocvn</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>m2fcsfyjkuxb</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>m3fdfocdoewn</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>@worrisome/reutil</code></td><td>keyval new-logic family</td></tr><tr><td>Malicious npm package</td><td><code>testdgdbcsd</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>tesgfvbncsdbcv</code></td><td>Microsoft typosquat family</td></tr><tr><td>Malicious npm package</td><td><code>mndsxcusiwlk1</code></td><td>keyval new-logic family</td></tr><tr><td>Malicious npm package</td><td><code>mn2adskhweox</code></td><td>keyval new-logic family</td></tr><tr><td>Malicious npm package</td><td><code>mn3sadkoiewu</code></td><td>keyval new-logic family</td></tr><tr><td>Malicious npm package</td><td><code>mn4xcouzvhus</code></td><td>keyval new-logic family</td></tr><tr><td>Malicious npm package</td><td><code>mbxcnsuwgs1</code></td><td>keyval new-logic family</td></tr><tr><td>Malicious npm package</td><td><code>skxcmwuncbg2</code></td><td>keyval new-logic family</td></tr><tr><td>Malicious npm package</td><td><code>mobiwaefhxc3</code></td><td>keyval new-logic family</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/malicious-npm-packages-clickfix-phishing/">npm Packages Exploited for ClickFix Phishing</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/malicious-npm-packages-clickfix-phishing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hackers Target ASOS Accounts Using Stolen Login Credentials</title>
		<link>https://firsthackersnews.com/asos-data-breach-customer-accounts/</link>
					<comments>https://firsthackersnews.com/asos-data-breach-customer-accounts/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 21:02:59 +0000</pubDate>
				<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[account takeover]]></category>
		<category><![CDATA[ASOS]]></category>
		<category><![CDATA[Credential Stuffing]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data Breach]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12278</guid>

					<description><![CDATA[<p>ASOS US Sales LLC has warned customers about unauthorized access to some accounts after attackers used login credentials</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/asos-data-breach-customer-accounts/">Hackers Target ASOS Accounts Using Stolen Login Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>ASOS US Sales LLC has warned customers about unauthorized access to some accounts after attackers used login credentials obtained from outside the company.</p>



<p>The activity was detected on <strong>July 28, 2026</strong>, and ASOS confirmed the incident the following day. The company launched an investigation and found that an unauthorized party may have used previously exposed usernames and passwords to access customer accounts.</p>



<p>The incident appears to involve <strong>credential stuffing</strong>, where attackers test stolen login details from other websites against new services. This type of attack often succeeds when people reuse the same password across multiple accounts.</p>



<h2 class="wp-block-heading">Customer Accounts Were Accessed</h2>



<p>According to ASOS, the information that may have been accessed varies by account. It could include names, email addresses, delivery or billing addresses, phone numbers, dates of birth, and information connected to social media accounts.</p>



<p>Some payment information may also have been visible, including the cardholder&#8217;s name, last four digits of the card, and expiration date.</p>



<p>ASOS said there is no indication that full card numbers, CVV codes, or ASOS account passwords were exposed.</p>



<p>The company moved quickly to contain the incident. On <strong>July 29</strong>, it blocked access to affected accounts and required customers to reset their passwords. Customers were notified by email on July 30.</p>



<p>ASOS also found suspicious transactions on a small number of accounts. The company said its security systems or fraud team blocked or canceled those transactions, and no further unauthorized activity was identified after containment.</p>



<h2 class="wp-block-heading">Password Reuse Remains a Major Risk</h2>



<p>The incident highlights how attackers can take over accounts even when a company itself has not suffered a direct password database breach.</p>



<p>When credentials from an unrelated data breach are reused on another website, attackers can try those same combinations automatically. A successful login can then expose personal information or potentially lead to fraudulent purchases.</p>



<p>Customers affected by the incident should:</p>



<ul class="wp-block-list">
<li>Create a new, unique ASOS password</li>



<li>Change the same password on other websites where it was reused</li>



<li>Enable multi-factor authentication whenever available</li>



<li>Review bank and payment accounts for unusual activity</li>
</ul>



<p>Users should pay particular attention to their <strong>email, banking, payment, and social media accounts</strong>, as these can provide attackers with access to additional services.</p>



<p>Customers who are concerned about possible identity misuse can also review their credit reports and consider additional protections such as a fraud alert or credit freeze.</p>



<p>The ASOS incident is another reminder that <strong>password reuse can turn an old data breach into a new account takeover</strong>. Using unique passwords and multi-factor authentication can significantly reduce the risk of attackers successfully accessing multiple accounts</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/asos-data-breach-customer-accounts/">Hackers Target ASOS Accounts Using Stolen Login Credentials</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/asos-data-breach-customer-accounts/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fake Security Scan Tricks Users Into Remote Access Scam</title>
		<link>https://firsthackersnews.com/fake-microsoft-security-scan/</link>
					<comments>https://firsthackersnews.com/fake-microsoft-security-scan/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 20:43:46 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft Scam]]></category>
		<category><![CDATA[Online scams]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Tech Support Scam]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12273</guid>

					<description><![CDATA[<p>A new web-based scam is using fake Microsoft-branded security scans to scare people into removing the antivirus software</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-microsoft-security-scan/">Fake Security Scan Tricks Users Into Remote Access Scam</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A new web-based scam is using fake Microsoft-branded security scans to scare people into removing the antivirus software protecting their computers and tricking them into a Microsoft security scan.</p>



<p>The fraudulent websites claim to detect serious security problems and warn that third-party antivirus products are no longer supported by Windows. In reality, the scan is fake and the warnings are designed to pressure users into taking unsafe actions, leading them to believe they need to perform a Microsoft security scan.</p>



<p>Researchers found that the websites collect basic information about a visitor’s browser and device, then use it to create a convincing but completely fabricated security report. The ultimate goal is to move victims into a fake refund or technical-support process.</p>



<h2 class="wp-block-heading"><strong>Fake Security Scan Creates a False Warning</strong></h2>



<p>Malwarebytes identified <strong>11 related websites hosted on the same server</strong>. The pages use similar branding and attempt to look like legitimate Microsoft security checks.</p>



<p>The sites display warnings about Windows updates, browser protection, memory security, firmware settings, and processor performance. However, a normal webpage cannot perform the deep system checks it claims to conduct.</p>



<p>The scammers combine genuine device information, such as screen size and operating system details, with pre-written warnings. This makes the fake report appear personalized and convincing.</p>



<p>The displayed security score is also manipulated, with results kept between <strong>13 and 30 out of 100</strong>, ensuring that visitors always believe their computer has serious problems.</p>



<p>The biggest red flag is the instruction to <strong>uninstall third-party antivirus software</strong>. Windows supporting Microsoft Defender does not mean other legitimate antivirus products are unsupported.</p>



<h2 class="wp-block-heading"><strong>The Fake Refund Trap</strong></h2>



<p>After the fake scan, victims are taken to a refund form that requests personal and financial information. The page also asks for details about antivirus software and remote-access tools.</p>



<p>The scammers can then use a phone call to convince victims that they need to provide remote access to complete a supposed refund.</p>



<p>Some warning signs include:</p>



<ul class="wp-block-list">
<li>A webpage claiming to perform a complete security scan</li>



<li>Extremely low security scores designed to create panic</li>



<li>Instructions to remove antivirus protection</li>



<li>Requests for banking or personal information</li>



<li>Pressure to install remote-access software</li>
</ul>



<p>According to Malwarebytes, information submitted through the fraudulent form is sent to the attackers through Telegram. Victims are then shown a message claiming that a refund representative will contact them shortly.</p>



<p>Once remote access is granted, scammers may be able to view files, access accounts, or monitor sensitive activity.</p>



<h2 class="wp-block-heading"><strong>How to Stay Safe</strong></h2>



<p>Users should never trust a random webpage that suddenly claims their computer has serious security problems. Legitimate security providers do not require users to uninstall antivirus software or give strangers remote access to their computers.</p>



<p>If you encounter one of these fake scans, <strong>close the webpage and verify the warning through the official website of your security provider</strong>.</p>



<p>Anyone who has already provided remote access should disconnect the affected device from the internet, remove the remote-access software, restore antivirus protection, and run a full security scan.</p>



<p>If banking information was shared, contact the bank immediately using an independently verified phone number and change important passwords from a separate trusted device.</p>



<p>The scam relies on fear and urgency rather than real technical analysis. Taking a moment to verify an alarming security warning can prevent a fake scan from becoming a much more serious account or financial compromise.</p>



<p><strong>Indicators of compromise (IoCs):-</strong><a href="https://cybersecuritynews.com/fake-windows-defender-alerts/" target="_blank" rel="noreferrer noopener"></a></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>IP address</td><td><code>157.230.180.90</code></td><td>Hosting server associated with the scam sites</td></tr><tr><td>Domain</td><td><code>detectsysscanner[.]at</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>detectsysscanner[.]com</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>detectsysscanner[.]de</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>detectsysscanner[.]in[.]net</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>detectsysscanner[.]xn--q9jyb4c</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>detsysscanner[.]com</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>detsysscanner[.]de</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>detsysscanner[.]xn--q9jyb4c</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>techsysscanner[.]com</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>techsysscanner[.]lol</code></td><td>Scam site domain</td></tr><tr><td>Domain</td><td><code>tlcscanner[.]com</code></td><td>Scam site domain</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/fake-microsoft-security-scan/">Fake Security Scan Tricks Users Into Remote Access Scam</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/fake-microsoft-security-scan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Strengthens Security With WhatsApp passkeys</title>
		<link>https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/</link>
					<comments>https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 16:57:05 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[account security]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[Passkeys]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Two-Step Verification]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12269</guid>

					<description><![CDATA[<p>WhatsApp is taking a major step toward stronger and simpler account security. More than 1 billion people are</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/">WhatsApp Strengthens Security With WhatsApp passkeys</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp is taking a major step toward stronger and simpler account security. More than <strong>1 billion people are now using WhatsApp passkeys</strong> to protect their WhatsApp accounts, making it one of the biggest passwordless authentication rollouts in the consumer technology space.</p>



<p>Along with this milestone, WhatsApp is introducing stronger two-step verification and additional information for calls from unknown numbers. These updates are designed to make accounts harder to compromise while helping users recognize potential scams.</p>



<p>The integration of WhatsApp passkeys is part of WhatsApp&#8217;s ongoing commitment to enhancing user safety and privacy.</p>



<h2 class="wp-block-heading"><strong>Passkeys Make WhatsApp Accounts Safer</strong></h2>



<p>Passkeys allow users to sign in using security features already available on their devices, such as a <strong>fingerprint, Face ID, or screen lock</strong>. Unlike traditional passwords or SMS codes, passkeys use cryptographic credentials that remain securely associated with the user&#8217;s device.</p>



<p>This makes them much more resistant to phishing, credential theft, and other attacks that depend on tricking users into revealing login information.</p>



<p>WhatsApp has now reached more than 1 billion passkey users and is expanding support for people who use multiple devices or switch between Android and iPhone.</p>



<p>Users can manage their passkeys through <strong>Settings &gt; Account &gt; Passkeys</strong>, where they can add or review their available credentials.</p>



<p>The milestone is significant because messaging accounts contain valuable personal information and are increasingly targeted by attackers looking to steal conversations, impersonate users, or target their contacts.</p>



<h2 class="wp-block-heading"><strong>Stronger Two-Step Verification</strong></h2>



<p>WhatsApp is also giving its two-step verification system a security upgrade. Instead of relying only on the traditional six-digit PIN, users can now create a stronger password.</p>



<p>The new password must be at least <strong>eight characters long</strong>, with at least one letter and one number. Users can also add special characters for additional protection.</p>



<p>A longer password provides a much larger combination of possible values than a short numeric PIN, making simple guessing and automated attacks more difficult.</p>



<p>Users who have been using an easy-to-guess PIN should take this opportunity to switch to a unique and stronger password.</p>



<h2 class="wp-block-heading"><strong>More Context for Unknown Calls</strong></h2>



<p>WhatsApp is also adding another layer of protection against scams by providing more information when users receive calls from unknown numbers on Android.</p>



<p>The incoming call screen can show details such as whether the number is from another country or whether the caller shares a group with the recipient.</p>



<p>This additional context can help users pause before answering a suspicious call or responding to an unexpected request. That is particularly useful because many scams rely on urgency and social engineering rather than technical exploits.</p>



<p>Together, <strong>passkeys, stronger two-step verification, and improved caller information</strong> give WhatsApp users several layers of protection against phishing, account takeovers, and social-engineering attacks.</p>



<p>For users, the message is straightforward: enable passkeys when available, use a strong two-step verification password, and be cautious when dealing with unfamiliar callers or unexpected requests for sensitive information.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/">WhatsApp Strengthens Security With WhatsApp passkeys</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hackers Use Microsoft Teams Phishing to Deploy SynkLoader Malware</title>
		<link>https://firsthackersnews.com/microsoft-teams-phishing-synkloader/</link>
					<comments>https://firsthackersnews.com/microsoft-teams-phishing-synkloader/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 21:19:15 +0000</pubDate>
				<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[IT support scam]]></category>
		<category><![CDATA[Microsoft Teams Phishing]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[SynkLoader malware]]></category>
		<category><![CDATA[Teams malware]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12263</guid>

					<description><![CDATA[<p>Microsoft Teams is being used in a new phishing campaign to deliver SynkLoader, a malware toolkit designed to</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-teams-phishing-synkloader/">Hackers Use Microsoft Teams Phishing to Deploy SynkLoader Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft Teams is being used in a new phishing campaign to deliver <strong>SynkLoader</strong>, a malware toolkit designed to gain control of Windows systems.</p>



<p>The attackers impersonate IT support staff and convince employees that they need to install a software fix. What looks like a routine helpdesk request can ultimately give attackers access to the victim&#8217;s system and valuable corporate information.</p>



<p>Security researchers at Expel identified the campaign and found that the malware components appeared to have been developed around late July 2026.</p>



<h2 class="wp-block-heading"><strong>Fake IT Support Leads to Malware Infection</strong></h2>



<p>The attack begins with a Teams conversation in which the threat actor poses as an internal IT service desk employee.</p>



<p>The victim is then directed to download an MSI file hosted on <strong>Azure Blob Storage</strong>, making the file appear more trustworthy.</p>



<p>The installer is presented as <strong>&#8220;PowerShell Cleaner&#8221;</strong> and drops additional files, including a ZIP archive and PowerShell scripts. These components launch the malware while keeping much of its activity hidden from the user.</p>



<p>SynkLoader can collect detailed information about the infected computer, including:</p>



<ul class="wp-block-list">
<li>Computer and username details</li>



<li>User privileges</li>



<li>Running processes and services</li>



<li>Active Directory information</li>



<li>System configuration</li>
</ul>



<p>The malware communicates with attacker-controlled infrastructure at regular intervals and can receive commands or additional Python code.</p>



<p>It also creates a randomly named scheduled task that helps the malware restart after a reboot or user logon.</p>



<h2 class="wp-block-heading"><strong>Fake Windows Lock Screen Steals Passwords</strong></h2>



<p>One of the more concerning components is <strong>PhishLocker</strong>, which displays a fake Windows 11 lock screen.</p>



<p>The screen is designed to look like a legitimate Windows password prompt and attempts to convince the victim to enter their Windows password.</p>



<p>The stolen password could then provide attackers with access to additional corporate services, particularly in environments where the same credentials are used across multiple applications.</p>



<p>Another component, called <strong>TrafficRedirector</strong>, can act as a reverse proxy through the infected computer. This could allow attackers to access internal services or route internet traffic through the victim&#8217;s corporate connection.</p>



<p>Researchers also identified capabilities for remote PowerShell access and VNC-based remote control, giving attackers additional ways to interact with a compromised system.</p>



<h2 class="wp-block-heading"><strong>How Organizations Can Reduce the Risk</strong></h2>



<p>Employees should be cautious when receiving unexpected IT support requests through Teams. Any request to install software should be verified through a trusted internal communication channel before proceeding.</p>



<p>Security teams should monitor for:</p>



<ul class="wp-block-list">
<li>Unexpected external Teams communications</li>



<li>Unapproved MSI downloads</li>



<li>Newly created scheduled tasks</li>



<li>Suspicious PowerShell activity</li>



<li>Unusual in-memory execution</li>



<li>Connections to known malicious infrastructure</li>
</ul>



<p>Teams audit logs and endpoint telemetry should also be preserved when investigating suspected infections.</p>



<p>The campaign highlights an important security lesson: <strong>trusted communication platforms can become powerful delivery channels when attackers successfully impersonate internal support teams.</strong></p>



<h2 class="wp-block-heading"><strong>IoCs</strong></h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Type</th><th class="has-text-align-left" data-align="left">Indicator</th><th class="has-text-align-left" data-align="left">Description</th></tr></thead><tbody><tr><td>URL</td><td><code>https://filereserve.blob.core.windows.net/vgnghuyk/331331.msi</code></td><td>Initial installer URL sent through Teams</td></tr><tr><td>SHA-256</td><td><code>151D2A7F52F047638CA8AD80C859C6BFE04D7510FB10933817FA0E3BA5D07A11</code></td><td>Initial installer</td></tr><tr><td>SHA-256</td><td><code>80F08360BA768B152B71ABB1CAB557F552A13DE18C83FE8E6396A197FEEC9185</code></td><td>First-stage payload</td></tr><tr><td>SHA-256</td><td><code>209F69A6CA859F05C954096B30391A43FDA33C9ED264DFDCCF806697F04B06A8</code></td><td>ZIP archive containing loader</td></tr><tr><td>SHA-256</td><td><code>D150C70D2732DF17AA77991B9EBF4C896F044445E900978581D9598DFA5DC98C</code></td><td>Main loader</td></tr><tr><td>SHA-256</td><td><code>61F961CFEBDF9967844526649B4B75BBA5B1B83210B70AA1BFFE3F64E6AC3112</code></td><td>PowerShell executor DLL</td></tr><tr><td>SHA-256</td><td><code>8207D8D949530EA063FFD5D47EE81B74BF718EC0A4755E2349E6AF9B91E92DC1</code></td><td>DLL loader</td></tr><tr><td>SHA-256</td><td><code>C4ACDA412774C292F0DB5D64467A2DD09282CDEA43C41967E8BF90F6298ACCF3</code></td><td>Profiling module loader</td></tr><tr><td>SHA-256</td><td><code>63622C1DDB3E2A9F11CAC192E13AC7494F558516B19D5D8F140F6D0D4D38EA84</code></td><td>Persistence module loader</td></tr><tr><td>SHA-256</td><td><code>A335E75B78B601EBC5C258975D95FD79AA21F836FC6B79D82E9A22C596133F07</code></td><td>Fake lock screen loader</td></tr><tr><td>SHA-256</td><td><code>0428FBDEFA8DDA10CE8FC12B1B516641E83CD5088388168E3F1A0BE1432B4077</code></td><td>Persistence module DLL</td></tr><tr><td>SHA-256</td><td><code>CB1C657F74B9E57F5E81126179128E8DB949D1D4196BE9DCB890341E222FD384</code></td><td>Fake lock screen DLL</td></tr><tr><td>Domain</td><td><code>neversoftmain.net</code></td><td>SynkLoader command-and-control domain</td></tr><tr><td>Domain</td><td><code>rootfarmapp.net</code></td><td>SynkLoader command-and-control domain</td></tr><tr><td>Domain</td><td><code>tripinupdate.net</code></td><td>SynkLoader command-and-control domain</td></tr><tr><td>Domain</td><td><code>dondermicapp.net</code></td><td>TrafficRedirector command-and-control domain</td></tr><tr><td>Domain</td><td><code>aroclenetapp.net</code></td><td>VNC module command-and-control domain</td></tr></tbody></table></figure>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-teams-phishing-synkloader/">Hackers Use Microsoft Teams Phishing to Deploy SynkLoader Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-teams-phishing-synkloader/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Zimbra Bug Exploited in the Wild</title>
		<link>https://firsthackersnews.com/zimbra-flaw-active-attacks/</link>
					<comments>https://firsthackersnews.com/zimbra-flaw-active-attacks/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 17:21:20 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[CVE-2026-73570]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[vulnerability impact]]></category>
		<category><![CDATA[Zimbra]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12260</guid>

					<description><![CDATA[<p>CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical command-injection vulnerability affecting Zimbra Collaboration</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zimbra-flaw-active-attacks/">Critical Zimbra Bug Exploited in the Wild</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>CERT Polska has warned that threat actors are actively exploiting <strong>CVE-2026-73570</strong>, a critical command-injection vulnerability affecting Zimbra Collaboration Suite.</p>



<p>The flaw allows remote, unauthenticated attackers to execute operating system commands with the privileges of the <code>zimbra</code> user. This creates a serious risk for organizations running internet-facing Zimbra mail servers.</p>



<h2 class="wp-block-heading">How the Zimbra Flaw Can Be Exploited</h2>



<p>The vulnerability is associated with Zimbra&#8217;s <strong>SNMP trap functionality</strong>. Exploitation is possible when the <code>snmp_notify</code> parameter is enabled and the <code>swatchdog</code> service is running.</p>



<p>Since <code>swatchdog</code> is enabled by default, systems using the affected SNMP configuration may be exposed without requiring an attacker to have valid credentials.</p>



<p>Successful exploitation could give attackers access to the underlying mail server, allowing them to run commands, create or modify files, steal email data, deploy web shells, establish persistence, or attempt to move deeper into the organization&#8217;s network.</p>



<h2 class="wp-block-heading">Active Exploitation and Detection</h2>



<p>CERT Polska has confirmed that the vulnerability is being used in an ongoing attack campaign, making this more than a theoretical security concern.</p>



<p>Zimbra has addressed the issue in <strong>version 10.1.20</strong>. Administrators should verify their installed version and upgrade affected systems as soon as possible.</p>



<p>Organizations that cannot patch immediately should review whether SNMP trap functionality is required and check if the <code>snmp_notify</code> configuration is enabled.</p>



<p>Security teams should also inspect <code>/var/log/zimbra.log</code> for unusual <strong>&#8220;Service status change&#8221;</strong> entries. Unexpected service names, commands, or changes between running and stopped states could indicate malicious activity.</p>



<p>It is also important to search for recently created or modified files owned by the <code>zimbra</code> user, particularly in:</p>



<ul class="wp-block-list">
<li><code>/opt/zimbra/jetty/webapps/</code></li>



<li><code>/opt/zimbra/jetty_base/webapps/</code></li>



<li><code>/tmp/</code></li>
</ul>



<p>Look for unfamiliar JSP files, scripts, archives, executable files, or heavily obfuscated content. Unexpected outbound connections from the Zimbra server should also be investigated.</p>



<h2 class="wp-block-heading"><strong>What Organizations Should Do</strong></h2>



<p>Organizations running vulnerable Zimbra installations should <strong>prioritize upgrading to version 10.1.20 or a later fixed release</strong>.</p>



<p>If compromise is suspected, isolate the affected server, preserve relevant logs and suspicious files for forensic investigation, rotate potentially exposed credentials, and check other connected systems for signs of lateral movement.</p>



<p>The active exploitation of CVE-2026-73570 highlights why <strong>internet-facing email infrastructure requires rapid patching and continuous monitoring</strong>. Patching should be followed by log analysis and threat hunting to ensure attackers have not already established persistence.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zimbra-flaw-active-attacks/">Critical Zimbra Bug Exploited in the Wild</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/zimbra-flaw-active-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
