• The Salesloft Drift data breaches of August 2025 stand as one of the most significant supply chain attacks in SaaS history, demonstrating how a single compromised integration can cascade into widespread organizational exposure.

    This sophisticated campaign, staged by the threat actor UNC6395, exploited OAuth token vulnerabilities to access sensitive data from over 700 organizations, including major cybersecurity vendors like Cloudflare, Palo Alto Networks, and Zscaler.

    The incident reveals critical weaknesses in third-party application security and offers valuable lessons for strengthening enterprise cyber resilience.

    Salesloft Drift breach attack timeline from GitHub compromise to data exfiltration
    Salesloft Drift breach attack timeline from GitHub compromise to data exfiltration

    Initial Compromise: The GitHub Account Breach

    The attack timeline reveals a methodical approach that began months before the public disclosure. According to Mandiant’s investigation, the threat actor UNC6395 first gained access to Salesloft’s GitHub account in March 2025, maintaining persistent access through June 2025.

    This initial compromise represents a critical security failure that went undetected for three months.

    During this extended access period, the attackers demonstrated sophisticated operational security by conducting reconnaissance activities across both the Salesloft and Drift application environments.

    They systematically downloaded content from multiple repositories, added guest users, and established workflows that would later facilitate the mass data exfiltration campaign.

    This extended time allowed the threat actors to thoroughly understand the target environment and identify the most valuable attack vectors.

    The GitHub compromise highlights a fundamental challenge in modern software development: the security of code repositories and development infrastructure.

    Salesloft has not disclosed how the initial GitHub access was obtained, but this gap in transparency has drawn criticism from security analysts who emphasize the importance of understanding root causes for effective remediation.

    OAuth token compromise attack flow diagram

    Drift Platform Exploitation and OAuth Token Theft

    Following their reconnaissance phase, the attackers pivoted to exploit Drift’s Amazon Web Services (AWS) environment, where they successfully obtained OAuth tokens for Drift customers’ technology integrations.

    This represents the critical supply chain vulnerability that enabled the widespread attack across hundreds of organizations.

    OAuth tokens serve as digital keys that authorize applications to access user data across different platforms without requiring password authentication.

    In the case of Drift, these tokens enabled the chatbot platform to integrate with customer systems like Salesforce, Google Workspace, and other business applications.

    By stealing these tokens, UNC6395 effectively inherited the same trusted access privileges, allowing it to bypass traditional security controls.

    The technical sophistication of this phase is evident in the attackers’ ability to access AWS-hosted OAuth credentials and extract them without detection.

    This suggests a deep understanding of cloud infrastructure and token management systems, characteristic of advanced persistent threat (APT) groups.

    Between August 8 and 18, 2025, UNC6395 launched a systematic data exfiltration campaign targeting Salesforce instances connected through Drift integrations. The attackers employed sophisticated techniques to maximize data theft while attempting to evade detection.

    The primary objective of the campaign was credential harvesting rather than immediate data monetization. UNC6395 systematically searched through exfiltrated data for valuable secrets, including:

    • Amazon Web Services (AWS) access keys (AKIA format)
    • Snowflake-related access tokens
    • VPN credentials and configuration information
    • Generic passwords and authentication strings
    • API keys and service account credentials

    This focus on credential harvesting indicates a strategic approach aimed at enabling secondary attacks and lateral movement across victim environments.

    The stolen credentials could provide attackers with persistent access to cloud infrastructure and business-critical systems far beyond the initial Salesforce breach.

    Companies Affected

    The breach impacted a staggering number of organizations, with Google Threat Intelligence Group confirming that hundreds of companies were affected.

    Among the publicly disclosed victims are several prominent cybersecurity vendors, highlighting the indiscriminate nature of supply chain attacks:

    • Cloudflare: Confirmed unauthorized access to Salesforce case objects between August 12-17, 2025, with 104 API tokens discovered and rotated
    • Palo Alto Networks: Disclosed compromise of CRM platform containing business contact information and basic case data
    • Zscaler: Acknowledged impact on Salesforce data, including customer licensing and commercial information
    • Tenable: Reported exposure of customer support case information and business contact details
    • Proofpoint: Confirmed as affected in multiple security advisories
    • Dynatrace: Reported limited exposure of business contact information with no impact to core products
    • Qualys: Confirmed limited Salesforce access with no impact to production environments
    • CyberArk: Disclosed compromise of CRM data while emphasizing no customer credential exposure
    • Wealthsimple: Reported more extensive impact, including customer government IDs and personal information.

    Root Cause Analysis: Systemic Security Failures

    The Salesloft Drift breach reveals multiple interconnected security failures that combined to create a catastrophic supply chain vulnerability:

    The initial GitHub compromise suggests inadequate security controls around code repositories and development infrastructure. Key failures include:

    • Insufficient access controls and monitoring for critical development accounts
    • Lack of detection capabilities for unauthorized repository access
    • Extended dwell time (3+ months) without detection of malicious activity

    The ability of attackers to access and steal OAuth tokens from AWS environments indicates significant shortcomings in credential management:

    • Inadequate protection of high-value authentication tokens
    • Insufficient segmentation between development and production environments
    • Lack of anomaly detection for OAuth token usage patterns

    Organizations demonstrated insufficient oversight of third-party integrations:

    • Over-permissive OAuth scopes granting excessive access to integrated applications
    • Inadequate monitoring of third-party application behavior
    • Lack of regular security assessments for connected applications

    Detection and Response Gaps

    The extended duration of malicious activity (10+ days) reveals detection and response deficiencies:

    • Insufficient real-time monitoring of API usage patterns
    • Delayed recognition of anomalous bulk data extraction activities
    • Inadequate threat intelligence sharing between vendors and customers

    Mitigation Strategies

    Based on the lessons learned from this incident, organizations should implement comprehensive mitigation strategies addressing both immediate and long-term security improvements:

    Immediate Response Actions

    OAuth Token Security Hardening:

    • Implement sender-constrained access tokens using mutual TLS (mTLS) or DPoP (Demonstrating Proof-of-Possession)
    • Establish refresh token rotation policies for public clients
    • Deploy real-time monitoring for OAuth token usage anomalies

    Third-Party Integration Review:

    • Conduct comprehensive audits of all connected applications and their permissions
    • Implement least-privilege principles for OAuth scopes and API access
    • Establish regular security assessments for critical integrations

    Enhanced Monitoring and Detection:

    • Deploy advanced analytics for API usage patterns and bulk data operations
    • Implement real-time alerting for suspicious SOQL query activities
    • Establish baseline behavioral profiles for legitimate application usage

    Strategic Security Improvements

    Supply Chain Risk Management:
    Organizations must implement comprehensive third-party risk management programs:

    • Conduct rigorous vendor security assessments before integration
    • Establish continuous monitoring of vendor security postures
    • Implement contractual security requirements and SLAs

    Zero Trust Architecture Implementation:

    • Apply zero-trust principles to all third-party integrations
    • Implement continuous verification and least-privilege access controls
    • Deploy network segmentation to limit lateral movement potential

    Development Security Enhancement:

    • Implement comprehensive security controls for code repositories
    • Deploy real-time monitoring for development environment access
    • Establish secure software development lifecycle (SDLC) practices

    The incident demonstrates how sophisticated threat actors can exploit trusted relationships to achieve widespread impact across hundreds of organizations simultaneously.

    As supply chain attacks continue to evolve in sophistication and scale, the lessons learned from this breach will be crucial for organizations seeking to protect themselves against future threats.

    The key is not just to implement individual security controls, but to build comprehensive, integrated security programs that can adapt to the dynamic nature of modern cyber threats.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Lessons from Salesforce/Salesloft Drift Data Breaches – Detailed Case Study appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to probe Microsoft and hold it responsible for what he called “gross cybersecurity negligence” that enabled ransomware attacks on U.S. critical infrastructure, including against healthcare networks. “Without timely action, Microsoft’s culture of negligent cybersecurity, combined with its de facto monopolization of the

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Four Kenyan filmmakers became victims of sophisticated surveillance when FlexiSPY spyware was covertly installed on their devices while in police custody, according to forensic analysis conducted by the University of Toronto’s Citizen Lab.

    The incident occurred on or around May 21, 2025, after authorities seized the devices during arrests connected to allegations surrounding the BBC documentary “Blood Parliament.”

    The filmmakers—MarkDenver Karubiu, Bryan Adagala, Nicholas Wambugu, and Christopher Wamae—were arrested on May 2 at a Nairobi studio on charges of publishing false information.

    Though released without charges the following day, their electronic devices remained in police custody until July 10, providing a window for the unauthorized spyware installation.

    CPJ analysts noted that the FlexiSPY installation represents a significant breach of journalistic privacy and security.

    The commercially available surveillance tool grants operators comprehensive access to victims’ digital communications, including real-time monitoring of messages, emails, and social media activities.

    Senior researcher John Scott-Railton emphasized that the spyware provides “silent, secret access to all sorts of private business and information about their journalism.”

    FlexiSPY markets itself as a monitoring solution for parents and employers, advertising capabilities that extend far beyond basic surveillance.

    The software can record phone calls, track device locations and website visits, capture passwords, download photos and videos, and even activate device microphones for environmental listening.

    This comprehensive surveillance capability makes it particularly concerning when deployed against journalists and media professionals.

    Advanced Persistence and Monitoring Capabilities

    The FlexiSPY spyware demonstrates sophisticated persistence mechanisms designed to maintain long-term access to compromised devices.

    Once installed, the malware operates stealthily in the background, continuously transmitting data to remote servers while avoiding detection by standard security measures.

    The software’s architecture allows it to survive device reboots and resist removal attempts through hidden system-level integration.

    The spyware’s monitoring capabilities extend to encrypted messaging platforms, potentially compromising secure communications that journalists rely upon for source protection.

    By intercepting data before encryption occurs at the application level, FlexiSPY can capture sensitive information that would otherwise remain protected.

    This functionality poses particular risks for investigative journalists who depend on confidential communications with sources and colleagues.

    The incident highlights growing concerns about state surveillance of media professionals and the weaponization of commercial spyware against press freedom advocates worldwide.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post Kenyan Filmmakers Installed With FlexiSPY Spyware That Monitors Messages and Social Media appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A previously unknown advanced persistent threat (APT) group has unleashed a new fileless malware framework, dubbed EggStreme, in a highly targeted espionage campaign against strategic organizations.

    Emerging in early 2024, EggStreme exploits the legitimate Windows Mail executable (WinMail[.]exe) to sideload a malicious library, allowing attackers to achieve in-memory code execution without writing decrypted payloads to disk.

    This technique evades traditional file-based defenses and has set off alarms among security teams operating in sensitive sectors.

    The attack chain begins when a logon script delivered via an exposed SMB share executes WinMail[.]exe from the user’s AppData directory.

    Instead of loading the genuine .NET runtime library, the binary inadvertently loads mscorsvc[.]dll, which contains the first stage loader.

    Once loaded, this DLL establishes a reverse shell by invoking cmd[.]exe and creating read/write pipes to a command-and-control (C2) server.

    Lateral movement and persistence are then orchestrated through hijacked Windows services that run with elevated privileges.

    Bitdefender analysts noted that the EggStreme framework is composed of multiple tightly integrated components, each responsible for a distinct phase of the operation.

    The EggStremeLoader, registered as a service, reads an encrypted payload file (ielowutil[.]exe[.]mui) and extracts two more layers: a reflective loader and the core backdoor agent.

    By leveraging reflective injection into trusted processes like winlogon.exe or explorer.exe, the adversary ensures continuous execution in memory.

    This multi-stage approach, with each layer decrypted and injected only when needed, makes detection exceedingly difficult.

    In its final form, the EggStremeAgent establishes a gRPC-based communication channel secured by mutual TLS, authenticating with certificates issued by a shared malicious certificate authority.

    EggStreme multi-stage infection flow (Source – Bitdefender)

    Once the backdoor is in memory, its 58 commands enable remote fingerprinting, file manipulation, registry operations, process injection, and sophisticated lateral movement such as RPC scans and WMIC-based remote process creation.

    Infection Mechanism and DLL Sideloading

    EggStreme’s initial infection leverages a subtle but powerful code snippet to hijack the search order for Windows libraries.

    EggStremeWizard (Source – Bitdefender)

    By placing a malicious DLL alongside WinMail.exe, the malware forces the legitimate binary to load attacker-controlled code. A representative snippet is shown below:-

    // Pseudo-code illustrating DLL sideloading
    HANDLE hModule = LoadLibraryA("mscorsvc[.]dll");
    if (hModule) {
        FARPROC pFunc = GetProcAddress(hModule, "CorBindToRuntime");
        if (pFunc) {
            pFunc();
        }
    }

    When WinMail.exe calls LoadLibraryA("mscorsvc[.]dll"), the Windows loader searches the local directory first, finding the malicious DLL instead of the system version.

    The loader decrypts its payload using an RC4 key ("Cookies"), checks for an on-disk configuration at %APPDATA%\Microsoft\Windows\Cookies\Cookies[.]dat, and updates its in-memory C2 list accordingly.

    The initial handshake comprises a 32-byte RC4-encrypted key exchange, ensuring integrity before the shell is created.

    Persistence is achieved through two complementary approaches. In some instances, the attackers alter the ServiceDLL registry value under HKLM\SYSTEM\CurrentControlSet\Services\<ServiceName>\Parameters to point to a malicious DLL.

    In others, they replace service binaries and grant SeDebugPrivilege, allowing the malicious payload to run under the context of a trusted Windows service.

    Both methods ensure that EggStreme components are reloaded on every reboot, maintaining a resilient foothold.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post New EggStreme Malware With Fileless Capabilities Leverages DLL Sideloading to Execute Payloads appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In early May 2025, cybersecurity researchers began tracking a novel Remote Access Trojan (RAT) targeting Chinese-speaking users via phishing sites hosted on GitHub Pages.

    Masked as legitimate installers for popular applications, the initial ZIP archives contained malicious executables engineered to bypass sandbox and virtual machine defenses.

    Once executed, the first-stage shellcode performs time stability analysis using QueryPerformanceCounter and examines hardware configurations—disk space and CPU cores—to identify analysis environments and terminate if suspicions arise.

    Attack chain (Source – Zscaler)

    This meticulous evasion strategy ensures that kkRAT rarely triggers alerts during automated detonation.

    Over the next stages, kkRAT deploys advanced anti-analysis techniques, dynamically resolving Windows API functions through single-byte XOR obfuscation and decrypting subsequent shellcodes with simple XOR transforms.

    In the second stage, the malware unloads and disables network adapters to sever AV/EDR communications, enumerates processes associated with Chinese security vendors, and employs a vulnerable driver (RTCore64.sys) to remove registered callbacks from kernel-mode defenses.

    Zscaler analysts noted that kkRAT even alters registry values for 360 Total Security to disable network checks and schedules tasks under SYSTEM privileges to repeatedly kill protection processes upon user logon.

    By the third stage, kkRAT retrieves a heavily obfuscated shellcode named 2025.bin from hardcoded URLs, decodes Base64-encoded instructions in output.log, and selects download URLs based on the victim process’s filename.

    The extracted archives contain legitimate executables sideloaded with malicious DLLs that decrypt the final payload—kkRAT itself—using a six-byte XOR key at offset 0xD3000.

    Zscaler researchers identified this seamless use of sideloading to deploy multiple RAT variants, including ValleyRAT and FatalRAT, but the newly discovered kkRAT blended features from both Ghost RAT and Big Bad Wolf.

    In its operation, kkRAT establishes a TCP connection to its command-and-control server, compresses data via zlib, and applies an additional XOR-based encryption layer.

    Phishing page impersonating Ding Talk (Source – Zscaler)

    A sample Python snippet used to decrypt captured traffic demonstrates this two-phase process:-

    import zlib
    def decrypt_packet(data, key):
        compressed = bytes(b ^ key for b in data)
        return zlib.decompress(compressed)

    Infection Mechanism

    Upon execution of the sideloaded DLL, kkRAT reads its encrypted configuration—C2 IP, port, version, and group identifier—and constructs a REGISTRATIONINFO struct containing detailed device fingerprints such as OS version, CPU frequency, memory size, installed antivirus signatures, and the presence of messaging applications.

    This thorough profile allows attackers to prioritize high-value targets. Uniquely, kkRAT inspects the clipboard for cryptocurrency wallet addresses (Bitcoin, Ethereum, Tether) and replaces them with attacker-controlled addresses via the 0x4D command, a tactic designed to hijack transactions silently.

    Once persistence is established through startup folder shortcuts or registry run keys, kkRAT remains resident, awaiting further instructions to load plugins—ranging from remote desktop management to process termination—and relay network traffic through Go-based SOCKS5 proxies.

    Through its layered encryption, sophisticated anti-analysis checks, and financial theft capabilities, kkRAT represents a significant evolution in commodity RAT toolkits, underscoring the persistent threat of supply-chain style malware delivery.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post kkRAT Employs Network Communication Protocol to Steal Clipboard Contents appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cornwell Quality Tools has disclosed a significant data breach that compromised the sensitive information of nearly 104,000 individuals.

    The incident involved unauthorized access to the company’s network, resulting in the exposure of both personally identifiable information (PII) and protected health information (PHI).

    According to the company’s report, the security incident was first identified on or around December 12, 2024, when an unauthorized third party successfully infiltrated Cornwell’s internal computer systems.

    A subsequent investigation determined that the attackers had accessed and potentially exfiltrated files containing a vast amount of sensitive data.

    The breach affected a total of 103,782 people. The inclusion of protected health information suggests the exposed data could belong to employees enrolled in company health plans, in addition to other individuals whose data was stored on the compromised network.

    Cornwell Quality Tools Data Breach

    The scope of the compromised data is particularly concerning due to its highly sensitive nature. The investigation confirmed that stolen information includes full names, Social Security Numbers, detailed medical information, and financial account numbers.

    The combination of PII and PHI makes victims highly susceptible to a range of malicious activities. This type of comprehensive data set is highly valued by cybercriminals, who can use it for sophisticated identity theft schemes, financial fraud, and targeted phishing attacks that leverage personal health details for credibility.

    Cornwell Quality Tools began notifying the affected individuals via postal mail on September 4, 2025, nearly nine months after the initial breach was discovered.

    The notification letters provide details about the incident and are intended to inform individuals whose data was confirmed to be involved.

    The significant delay between the breach’s discovery and the notification can leave victims unknowingly exposed to fraud for an extended period. However, such timelines can sometimes result from complex forensic investigations.

    Individuals who receive a data breach notification from Cornwell are urged to take immediate steps to protect themselves. Security experts recommend that victims closely monitor their financial statements and credit reports for any unusual activity.

    Placing a credit freeze or fraud alert with the major credit bureaus is a critical proactive measure to prevent criminals from opening new accounts.

    Furthermore, all affected parties should be highly vigilant against potential phishing emails, text messages, or phone calls that may use the stolen information to appear legitimate. The notification letter provides more information regarding the legal rights of those impacted.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post Cornwell Quality Tools Data Breach – 100,000 Users Data Was Compromised appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In recent months, cybersecurity researchers have observed a surge in malicious domain registrations linked to an emerging e-crime group known as PoisonSeed.

    First identified in April 2025, this actor has focused its efforts on impersonating legitimate cloud-based email platforms, most notably SendGrid, to harvest enterprise credentials.

    By embedding fake Cloudflare CAPTCHA interstitials and Ray ID data into their phishing infrastructure, PoisonSeed has managed to evade cursory detections and lure unsuspecting targets into surrendering login information.

    Domaintools analysts noted that between June and September 2025, PoisonSeed registered over twenty domains that closely mimic SendGrid’s login portals.

    These domains were often hosted on IP ranges assigned to the Global-Data System IT Corporation (AS42624) and registered through NiceNIC International Group Co., a registrar that has attracted scrutiny for its lax verification processes.

    Researchers identified subtle misspellings and additional path structures—such as “sgportalexecutive[.]com” and “internal-sendgrid[.]com”—designed to exploit both user trust and automated screening tools.

    The impact of PoisonSeed’s campaign extends beyond simple credential theft. Once enterprise credentials are compromised, the actor deploys lateral movement techniques within corporate environments to expand access.

    This progression can lead to data exfiltration, fraudulent fund transfers, and even ransomware deployment.

    In one unreported incident, PoisonSeed leveraged harvested credentials to send internal phishing invitations to high-value targets, ultimately siphoning sensitive financial data.

    Despite the sophistication of these campaigns, detection evasion remains a core focus for PoisonSeed.

    By integrating fake JavaScript-based CAPTCHA logic and dynamically generated Ray IDs, the group ensures that each interstitial appears unique.

    Moreover, their use of co-hosting on legitimate-looking domains adds an additional layer of stealth, delaying incident response teams from isolating the malicious infrastructure.

    Infection Mechanism and Detection Evasion

    A closer examination of PoisonSeed’s infection mechanism reveals a multi-stage process that capitalizes on human trust and automated filtering weaknesses.

    In the initial phase, victims receive an email purporting to originate from SendGrid, complete with legitimate-looking headers and tracking links.

    When the target clicks the link, they are redirected to a CAPTCHA challenge page that appears authentic.

    PoisonSeed embeds counterfeit session tokens to maintain the illusion of authenticity. Following validation, users are presented with a second form requesting their SendGrid credentials.

    At this juncture, the actor captures the submitted data before forwarding the victim to the legitimate SendGrid login page, minimizing suspicion.

    The use of chained redirects and script obfuscation ensures that traditional URL blocklists and signature-based defenses struggle to keep pace with the rapidly changing domain infrastructure.

    By continuously rotating domain names and leveraging compromised hosting environments, PoisonSeed maintains a resilient phishing operation that demands advanced threat intelligence and proactive monitoring to counter effectively.

    Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.

    The post PoisonSeed Threat Actor Registering New Domains in Attempt to Compromise Enterprise Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A significant vulnerability has been discovered in CoreDNS that could allow attackers to disrupt services by pinning DNS cache entries, effectively creating a denial of service for updates.

    The flaw, residing in the CoreDNS etcd plugin stems from a critical logic error where an etcd lease ID is misinterpreted as a Time-To-Live (TTL) value, leading to abnormally long caching periods for DNS records.

    The root of the vulnerability is found within the plugin/etcd/etcd.go file. The TTL() function incorrectly casts a 64-bit etcd lease ID into a 32-bit unsigned integer and uses this result as the DNS record’s TTL.

    Lease IDs are arbitrary identifiers for a lease grant and do not correlate with the duration of the lease. When a large lease ID is generated, its truncated value can represent an extremely long TTL, sometimes spanning decades.

    TTL Confusion Leads To Cache Pinning

    Downstream DNS resolvers and clients that receive this record will cache it for the specified duration.

    This enables a “cache pinning” attack, where an attacker can create a malicious or outdated DNS entry that persists for an exceptionally long time, preventing any future updates from being propagated to affected clients.

    An attacker with write access to the etcd data store, potentially through a compromised service account or a misconfigured environment, can exploit this flaw.

    The attacker would create or update a DNS record and attach a lease to it. The actual duration of the lease is irrelevant; only its ID matters.

    CoreDNS will then serve this record with the massive, misinterpreted TTL. Consequently, clients and resolvers will cache this stale information.

    Even if the malicious entry is corrected or deleted from etcd and CoreDNS is restarted, clients will continue to resolve the incorrect address until their local cache expires.

    This has a high availability impact, as critical service updates, IP address rotations, or failover procedures would be ignored by clients with a pinned cache entry.

    The integrity impact is considered low, as an attacker with etcd write access could already redirect services to malicious endpoints; however, the bug magnifies the persistence of such an attack.

    Affected Versions And Mitigation

    This vulnerability was introduced in CoreDNS version 1.2.0 and affects all subsequent versions that utilize the etcd a plugin for service discovery.

    The flaw was disclosed by GitHub user “@thevilledev,” who also contributed a fix. The recommended mitigation involves updating the TTL() function to correctly use etcd’s Lease API to determine the remaining time on a lease, rather than misusing the lease ID.

    Additionally, it is suggested that configurable minimum and maximum TTL limits be implemented to prevent extreme values from being served.

    Users of the CoreDNS etcd plugin are strongly advised to update to a patched version to prevent potential service disruptions.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post CoreDNS Vulnerability Let Attackers Pin DNS Cache And Deny Service Updates appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • London North Eastern Railway (LNER) has confirmed that passenger data was accessed following a cyber attack on one of its third-party suppliers.

    The breach involved unauthorized access to files containing customer contact details and information related to previous journeys.

    LNER announced it was made aware of the security incident and is treating the matter with the highest priority. According to the rail operator, the compromised information is limited to customer contact details and some travel history.

    The company was quick to reassure customers that no sensitive financial data, such as bank account or payment card information, was affected by the breach.

    LNER Train Passengers Data

    Furthermore, customer passwords remain secure as the compromised third-party system did not have access to this information.

    In response to the incident, LNER is working closely with cybersecurity experts and the affected supplier to conduct a thorough investigation.

    The primary goals are to understand the full scope of the unauthorized access and to ensure that appropriate safeguards are implemented to prevent similar incidents in the future.

    The company has stated that it will provide further updates as more information becomes available through its investigation.

    LNER’s core services, including ticket sales and train operations, are entirely unaffected by the security breach, and customers can continue to book travel and use the services as normal.

    LNER has issued guidance to its customers in the wake of the breach. Passengers are advised to be cautious of any unsolicited communications they may receive, particularly those that request personal information.

    These could be phishing attempts by malicious actors trying to leverage the stolen data. The company clarified that there is no need for customers to contact their banks, as no financial details were compromised.

    While password data was not accessed, LNER reminded customers that maintaining strong, unique passwords and changing them regularly is always good security practice. The company is focused on managing the situation and communicating transparently with those affected.

    Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

    The post UK Train Operator LNER Passengers Data Accessed In Cyber Attack appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In early May 2025, Unit 42 researchers observed multiple instances of AdaptixC2 being deployed to infect enterprise systems. Unlike many high-profile command-and-control (C2) platforms, AdaptixC2 has flown under the radar, with scant public documentation demonstrating its use in live adversary operations. Our research dissects AdaptixC2’s capabilities, deployment techniques, and evasion mechanisms to equip security teams […]

    The post Threat Actors Leveraging Open-Source AdaptixC2 in Real-world Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶