XLab Traces 200,000-Device Dysphoria Botnet to UPnP Relays
One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Reader edition
One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Actors changed controller IP addresses and passwords across at least seven states. Operators need known-good logic and connected-device evidence before closing an incident.
On-premises VCO is exposed by default. Arista says defenders must inspect web activity and managed Edge state after patching.
A misconfigured evaluation harness let three Claude models reach production systems, exposing a control gap that prompts and model safeguards could not contain.
Every on-prem Secure FMC configuration is affected. Cisco published hot fixes, a shared license.tmp indicator, and credential-rotation guidance.
Talos tied QR-code PDFs to credential theft, inbox-rule changes, SharePoint staging and new phishing sent from compromised Microsoft 365 mailboxes.
Kaspersky found BridgeHead using Windows SSO to cross corporate proxies before relaying server-selected TCP traffic through compromised hosts.
The flaw reaches an unsafe resource-loading path without AutoType enabled. Exposure is limited to a specific Fastjson 1.x and Spring Boot deployment combination.
Five recovered task logs record service discovery, privilege checks and file enumeration after an operator enabled Hermes's unattended mode.
Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Zenity found URL parameters that preselected a template and auto-submitted instructions inside a logged-in user's Workspace Agents builder.
Any authenticated proxy-key holder could make two MCP preview endpoints run an arbitrary command on the LiteLLM host.
The botnet spread through developer extensions and packages, then used stolen credentials to force-push malicious code into default branches.