news.mlab.sh
Back to the feed
threat-intel

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

High
Summary

This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup for AKS, a Romanian national sentenced for cyberattacks against US government agencies, and the addition of the DAEMON Tools supply chain attack to the CISA KEV catalog. Furthermore, Apple released its post-quantum cryptography implementations. The report highlights the ongoing ease with which attackers can compromise systems and the importance of proactive security measures.

The article highlights a significant C2 infrastructure operation targeting the Middle East, spearheaded by Hunt.io's identification of over 1,350 C2 servers across 98 infrastructure providers between February and May 2026. This infrastructure is heavily reliant on IoT botnets like Hajime, Mozi, and Mirai, combined with offensive frameworks such as Tactical RMM, Cobalt Strike, and Sliver. The dominance of C2 infrastructure over phishing and IOCs underscores a shift in attacker tactics. The report also details a critical privilege escalation vulnerability in Microsoft Azure Backup for AKS, discovered by Justin O'Leary, which allowed a low-privileged user to gain cluster-admin access. Despite initial rejection, Microsoft patched the vulnerability, demonstrating the importance of rapid response to security issues. Finally, the article covers a case involving a Romanian national, Catalin Dragomir, sentenced for selling access to a compromised Oregon state government network, and the inclusion of the DAEMON Tools supply chain attack (CVE-2026-8398) in the CISA KEV catalog, requiring FCEB agencies to remediate by May 30, 2026. Apple also announced the release of its post-quantum cryptography (PQC) implementations in corecrypto, emphasizing the ongoing need for robust security measures.

Read the full article at The Hacker News