XLab Traces 200,000-Device Dysphoria Botnet to UPnP Relays
One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Read article →Reader view
Choose the default article length.
Page 2 of 3
One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Read article →Actors changed controller IP addresses and passwords across at least seven states. Operators need known-good logic and connected-device evidence before closing an incident.
Read article →On-premises VCO is exposed by default. Arista says defenders must inspect web activity and managed Edge state after patching.
Read article →A misconfigured evaluation harness let three Claude models reach production systems, exposing a control gap that prompts and model safeguards could not contain.
Read article →Every on-prem Secure FMC configuration is affected. Cisco published hot fixes, a shared license.tmp indicator, and credential-rotation guidance.
Read article →Talos tied QR-code PDFs to credential theft, inbox-rule changes, SharePoint staging and new phishing sent from compromised Microsoft 365 mailboxes.
Read article →Kaspersky found BridgeHead using Windows SSO to cross corporate proxies before relaying server-selected TCP traffic through compromised hosts.
Read article →The flaw reaches an unsafe resource-loading path without AutoType enabled. Exposure is limited to a specific Fastjson 1.x and Spring Boot deployment combination.
Read article →Five recovered task logs record service discovery, privilege checks and file enumeration after an operator enabled Hermes's unattended mode.
Read article →Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Read article →Zenity found URL parameters that preselected a template and auto-submitted instructions inside a logged-in user's Workspace Agents builder.
Read article →Any authenticated proxy-key holder could make two MCP preview endpoints run an arbitrary command on the LiteLLM host.
Read article →The botnet spread through developer extensions and packages, then used stolen credentials to force-push malicious code into default branches.
Read article →CVE-2026-6875 chained query evaluation with a sandbox escape, giving an unauthenticated attacker broad control of a ServiceNow instance and its connected proxy servers.
Read article →Push Security traced sponsored search ads to shared ChatGPT and Claude pages that handed visitors to fake desktop-app downloads.
Read article →A civil lawsuit targets a Telegram-based phishing-kit operation that Google links to 2.5 million texts and more than one million fraudulent URLs.
Read article →