Radar van Elk Solutions

Hackaday · Creativity & design

This Week in Security

This week's security news includes a major data breach at the FBI, a critical vulnerability in Meta's Muse agent, targeted attacks against Rust developers, and new exploits affecting Windows Defender and RSA encryption.

The FBI's jobs website was compromised by the ShinyHunters group, who exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud and steal 2 TB of employee data. ShinyHunters is known for demanding ransoms and threatening to leak stolen information.

Meta's Muse agent, an AI platform running on user computers, has a critical vulnerability. Attackers can redirect its transcription server to gain access to the agent's resources, including microphone and screen recording, and steal authentication tokens and user data.

A "ClickFix" attack, which tricks users into running malicious commands by presenting a fake authentication prompt, has shown success in compromising systems like the Muse agent.

Members of the Rust language team and prominent crate developers are being targeted by suspected North Korean state hackers. Attacks involve phishing attempts disguised as collaboration requests, leading to malware downloads.

The "NightmareEclipse" hacker has released "BigDiskBuster," a denial-of-service vulnerability targeting Windows Defender, preventing it from updating its signature database. Proof-of-concept code is available, and Microsoft has not yet released a patch.

Researchers have identified a new attack against RSA encryption that can significantly reduce the difficulty of breaking 1024-bit RSA, with potential implications for 2048 and 4096-bit keys. This could affect implementations like Apple and Cloudflare's Privacy Pass.

AI-samenvatting op basis van de bron.

Hackaday