Hackaday · Creativity & design
Security Incidents: FBI Breach, Muse Vulnerability, Rust Targeting, RSA Attacks
This week saw significant security events, including an FBI data breach, a critical vulnerability in Meta's Muse agent, targeted attacks against Rust developers, and new RSA encryption compromise methods.

ShinyHunters claims to have exploited a zero-day in Oracle PeopleSoft to access the FBI's jobs website, obtaining 2 TB of employee data from AWS GovCloud. They demand the FBI retract statements, threatening to release data.
Meta's Muse agent on macOS has a critical vulnerability allowing attackers to redirect its transcription server for unauthorized access to user data, including microphone and screen recordings.
A "ClickFix" attack can exploit the Muse agent by tricking users into running malicious commands. The agent has seen significant adoption on iOS and Android.
Rust developers are targeted by suspected North Korean hackers via phishing for conference calls, leading to malware downloads. This tactic is linked to previous supply chain poisoning.
The "NightmareEclipse" hacker released "BigDiskBuster," exploiting a Windows Defender vulnerability that prevents updates. No patch is available.
New attacks against RSA encryption can compromise 1024-bit keys and may affect 2048/4096-bit keys, potentially reducing breaking difficulty significantly.
These RSA attacks could impact implementations like Apple and Cloudflare's Privacy Pass, requiring billions of attempts but potentially feasible given daily connection volumes.
AI-samenvatting op basis van de bron.
Hackaday