Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach ...
Cisco says attackers exploited its Secure Email Gateway before Monday's disclosure and patch. An unauthenticated remote attacker can trigger it by sending an email and gain root-level command execution on cloud or on-premises appliances. Cisco found possible compromises among cloud customers and deployed mitigations there. The Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog. The actor and scope aren't known yet, so customers should patch immediately and hunt for compromise, though root access could let attackers erase evidence.
BambooToken branches into Linux
Lumen Technologies Black Lotus Labs researchers uncovered BambooToken, which is malware that uses the MQTT messaging protocol to control Windows and Linux systems. Lumen says it's been operating since February 2023, with activity through July across Asia and South America. It appears to reach Windows machines by sideloading a malicious DLL through legitimate Tendyron Corporation OnKey software, though Tendyron's certificate and build system weren't compromised. Newer versions collect extensive host data and load plugins, including one that inventories antivirus tools. Lumen says it found a dozen compromised entities and sees a possible China link.
CenterPoint breach claim hits 7M+
CenterPoint Energy says an unauthorized third party obtained personal information from some customers through an external-facing system. The utility serves roughly seven million customers across Indiana, Minnesota, Ohio, and Texas, and told the SEC that electricity and gas delivery weren't affected and it doesn't expect a material impact. The disclosure followed a hacker's claim of nearly 7.5 million stolen records and publication of a 2.5-gigabyte archive, along with a threat to target infrastructure. But SecurityWeek says it can't verify the archive and notes that claims like this can be exaggerated.
Ukraine puts police veteran on cyber
Ukrainian President Volodymyr Zelensky appointed Ihor Klymenko to lead the National Cybersecurity Coordination Center, which monitors threats, coordinates agencies, and oversees cyber strategy. Klymenko doesn't appear to have a technical cybersecurity background, but he's led Ukraine's National Police since 2019, including its cyber police, became interior minister in 2023, and was named head of the National Security and Defense Council last month. Zelensky says that experience will help coordinate responses to Russian cyber operations and criminal networks.
Big thanks to our sponsor, Vanta
Fake hires get a six-day head start
According to a HYPR Service survey of 500 US HR executives, fraudulent candidates make it into jobs in 42% of cases. Of those, only 3% are caught on day one, leaving fake hires with an average 5.73 days of unmonitored network access, while 20% stay undetected for up to three weeks. Human instinct catches 68% of detected fraud, and responsibility remains split between HR and security. These findings echo Cybersecurity and Infrastructure Security Agency warnings that adversaries use AI to win remote IT jobs and receive legitimate credentials, a tactic often linked to North Korean operators.
( Infosecurity Magazine )
WooCommerce flaw opens back door
Hackers are exploiting a premium @WooCommerce Wholesale Lead Capture plugin to upload PHP webshells and take over @WordPress sites. The unauthenticated file-upload flaw affects version 2.0.3.1 and older because attackers can add PHP to a user-controlled list of allowed file types. @Wordfence says it blocked more than 100,000 attacks, with spikes from June through August. Administrators should update and check upload folders, admin-ajax logs, and administrator accounts for signs of compromise.
Tajin turns cybercrime into marketplace
Recorded Future says it's mapped Tajin Group, a Chinese-speaking vendor selling phishing, payment-card theft, and money-laundering services through Telegram guarantee marketplaces. The group moved from Dabai Guarantee to Xinbi Guarantee around May and claims a 208,848-USDT (Tether) deposit, far above the usual vendor stake. Researchers say Tajin tests stolen cards across payment platforms, seeks partners who can abuse major card networks and @Apple Pay, and has bought or sold more than 100 Telegram Messenger usernames plus anonymous phone numbers.
KREMLIN forges its way into Chrome
Researchers at Elastic Security Labs have detailed KREMLIN, a Brazilian banking-malware toolkit that installs malicious extensions in Google Chrome and Microsoft Edge to steal credentials, cookies, session tokens, screenshots, and page data. The campaign starts with a victim manually running a disguised JavaScript file, then uses custom installers to forge Chromium integrity data and register the extension. Ethereum smart contracts let attackers change command-and-control and payload locations. Elastic registered a canary domain used by the malware and saw 1,515 infected systems check in, more than 98% of them in Brazil.
Spotify , Apple Podcasts , YouTube , RSS link , Amazon Music , add as an Alexa Skill , or "Cybersecurity Headlines" on your favorite podcast app.
Cybersecurity Headlines
To view or add a , sign in
More articles by CISO Series
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
