As humans, we always find a way to break stuff. That's evident in all the articles that we have for this week's review. Still, that will not deter us from continuing to break stuff because if we break them and fix them, it's better for a malicious user to break them and exploit them.
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
What got me interested in this article was the role that CSS played. It's been a while since I read articles that remind me that CSS is more than a stylesheet.
From the article:
The research follows two paths: abuse HTML and CSS that webmail already allows, or create a discrepancy between what a sanitizer approves and what the browser or application ultimately creates. Both can cross the boundary between an untrusted message and its trusted interface.
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
It's just the beginning. Attacks like this will be common in the future, and it will be up to defenders to stop them from happening.
Here is what's going on:
Dubbed Ghostjacking, the newly demonstrated attack builds on the same assumption: an external threat actor is able to plant instructions as text in logs or alerts to turn AI agents rogue.
The underlying issue, it says, is spread widely, as the attack targets three highly trusted platforms: Cloudflare, which routes 20% of all web traffic, Datadog, and Sentry.
Terabytes of credentials leaked in massive supply-chain attack
Yes, it's a lot of credentials. How did this happen? The use of a compromised AI package. For how long? 40 minutes.
From the article:
CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.
Zoom Bug Handed Attackers Full Control of Devices
You'll think that it's just another vulnerability that needs fixing. Yes, you're right. Now, why did I include it? The time it took for the researcher to develop the exploit and how they did it. What am I talking about?
Here you go:
What stands out is how quickly the exploit was built. The researchers who discovered it used AI prompts to develop the screen-sharing attack in under 24 hours, an illustration of how AI can lower the barrier to sophisticated cyberattacks.
The attack was designed to be silent. It required nothing from the victim. There was no visible warning and no interaction needed.
New Android malware relays bank cards to fraudsters while victims still hold them
Scammers will always find ways to steal your money. This is just another.
From the article:
In one 13-minute phone call, the victim installed a RAT onto their own device — everything after that was performed by the fraudster. By the end of the call, the fraudster had taken out a loan in the victim’s name through remote access to the victim’s mobile app, and was streaming their card data to a fake merchant terminal.
Hackers drained $130 million in Bitcoin from 7,300 'cold' wallets once billed as secure
It was billed as secure. It turns out that a flaw in the affected device's firmware led to predictable seed phrases that facilitated the theft by the attackers. This attack also reminds us of the sentence: No system is safe.
From the article:
In late July, Canada-based Coinkite Inc. told users that some Coldcard devices had produced vulnerable seed phrases — the strings of words used to access a wallet. By August 3, Galaxy Research said around 7,300 addresses had been compromised, with an estimated $130 million stolen.
Engineers at Block Inc. traced the issue to the wallets' random-number generation.
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
Top comments (0)