Exposed Server Reveals Aurora Operator's Breach Playbook Across 17 Organizations
An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Reader edition
An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
ErrTraffic lures lead users to run Cruciferra, which uses a vulnerable signed driver to terminate security processes before the Remus stealer runs.
Next.js fixed two unauthenticated code-execution paths involving AVIF processing and Windows servers. Self-hosted operators need 15.5.24 or 16.3.3.
Dindoor uses the signed Deno runtime, encoded stages, and a pre-persistence sandbox check. Hunt the fixed process and registry sequence beneath the changing payload.
Gitea’s patch API can turn repository content into server code execution. Upgrade to 1.27.2 or later and check server activity for signs of compromise.
CareCloud says forensic review confirmed patient data exfiltration. HHS reports 3.76 million affected people, while public records do not map specific fields to each person.
CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
A new Windows loader arrives through a fake Teams help desk; modules sent to Expel’s emulator phish passwords and tunnel into internal services.
An updated Android banking trojan blocks Google Play traffic, automates wireless ADB pairing, and targets 349 financial apps across 16 countries.
A 1.1 MB fake installer delivers Vidar, launches installed browsers headlessly, and copies credentials and sessions that can remain useful after cleanup.
Two exploited miniOrange SAML flaws can mint WordPress admin sessions. Seven independently versioned editions make ordinary update and vulnerability checks unreliable.
Kaspersky traced malware on DoFun-powered car displays from a trusted updater to ad fraud and a residential proxy. DoFun says it fixed the issue but published no fixed build.
The browser extension exposed vault tokens to untrusted page messages. Version 3.49.6 adds origin, frame, and nonce checks; later builds supersede it.