Palo Alto Networks disclosed a critical buffer overflow in the PAN‑OS User‑ID Authentication (Captive) Portal that allows unauthenticated remote code execution with root privileges and is already being exploited in the wild. No patches are available yet; fixes begin rolling out May 13–28, and admins should immediately restrict portal access to trusted internal zones or disable it if not required. Rapid7 notes a large exposed footprint and confirms attackers are targeting portals reachable from untrusted networks. Prioritize workarounds now and prepare for rapid patching when releases drop.
Source: Rapid7
Daemon Tools Supply‑Chain Attack: Trojanized Installers from Official Site Hit High‑Value Targets
Attackers tampered with Daemon Tools installers distributed via the software’s official website in a global supply‑chain incident, researchers report. While trojanized builds were broadly installed, a sophisticated backdoor was selectively deployed to a small set of systems, including government and scientific entities—suggesting targeted follow‑on operations. Organizations should verify installer signatures, reimage impacted hosts, and review egress for associated C2 indicators.
Source: SecurityWeek
State‑Backed Espionage Masquerades as Chaos Ransomware
Rapid7 details an intrusion that posed as a Chaos RaaS attack but aligns with Iran‑linked MuddyWater/Seedworm tradecraft, including credential theft via Microsoft Teams social engineering, MFA manipulation, long‑term persistence with DWAgent/AnyDesk, and data exfiltration—without encryption. Attribution hinges on shared code‑signing certificates and overlapping C2 infrastructure, underscoring how APTs increasingly use criminal tooling and branding to blur intent and slow response.
Source: Rapid7
CISA’s “CI Fortify” Push: Keep Critical Infrastructure Running Offline During Cyberattacks
CISA unveiled CI Fortify, a new initiative to help critical infrastructure operators pre‑plan isolation and recovery so essential services can function without reliable telecoms or internet during major cyber events. The program urges proactive disconnection from third‑party dependencies and development of offline operating modes—shifting resilience from theory to practice for grid, water, transportation, and healthcare providers.
Source: The Record
LLMs in the Kill Chain: Claude AI Used to Home In on OT Assets at Water Utility
Dragos observed threat actors leveraging Claude AI during an intrusion at a Mexican water and drainage utility, using the model to help identify operational technology assets and potential attack paths. The case highlights how general‑purpose AI can accelerate adversary recon in ICS/OT environments, raising urgency for strict network segmentation, egress controls, and monitoring of atypical analyst‑style queries from compromised hosts.
Source: SecurityWeek
Gemini CLI Flaw Opened Door to GitHub‑Driven Prompt Injection and Supply‑Chain Takeover
A now‑patched vulnerability in Google’s Gemini CLI could let attackers inject prompts into GitHub issues to seize control of an automated triage agent, leading to arbitrary code execution and potential supply‑chain compromise. Teams should update the CLI, harden agent permissions and tokens, and treat untrusted issue content as exploit input—adding guardrails and content validation to AI‑assisted DevOps flows.
Source: SecurityWeek
OceanLotus Using PyPI Wheel Packages to Deliver ZiChatBot on Windows and Linux
Kaspersky uncovered malicious PyPI wheel packages that appear legitimate but covertly drop a new ZiChatBot malware family across Windows and Linux systems. The campaign is attributed to OceanLotus (APT32), reinforcing the need for strict package provenance checks, pinned hashes, and pre‑deployment scanning in Python build chains.
Source: Securelist
You May Also Be Interested In...
When DNSSEC goes wrong: how Cloudflare handled the .de TLD outage
vm2 Node.js library flaws enable sandbox escape and arbitrary code execution
Attackers adopt Bun runtime to package and spread NWHStealer