Tag

Data Exfiltration

All articles tagged with #data exfiltration

Microsoft Ties 30+ Domains to MacSync MacOS Information Stealer Infrastructure
security5 days ago

Microsoft Ties 30+ Domains to MacSync MacOS Information Stealer Infrastructure

Microsoft Defender Experts linked more than 30 web domains to the MacSync Stealer infrastructure, tracing a macOS information stealer from payload delivery through exfiltration. The campaign uses interactive zsh terminals, curl-based payload retrieval, AppleScript-assisted execution, and staging in /tmp with HTTP PUT uploads carrying chunked data. Observed exfiltration patterns and recurring endpoints (/curl/, /dynamic?txd=, /gate build) reveal rotating infrastructure, while data collected includes credentials, keys, and sensitive files. Microsoft cautions users and urges monitoring of curl uploads, API-key headers, and domain changes; Apple’s macOS protections (Terminal paste protection, pasteboard blocking, AppleScript scanning) are also relevant. The report follows similar findings from RST Cloud, which noted a static API key across several domains and parallel C2 operation across a rotating set of domains.

Undocumented Copilot prompt bypass enables data exfiltration via malicious link
technology7 days ago

Undocumented Copilot prompt bypass enables data exfiltration via malicious link

Varonis researchers demonstrated a vulnerability in Microsoft 365 Copilot Enterprise: an undocumented URL parameter (?autorun=1) could auto‑execute prompts without user consent when a user clicked a crafted link, allowing exfiltration of passwords and other sensitive data. Microsoft mitigated the issue by disabling the ?q= prompt injection and later rolled out broader fixes, illustrating how guardrails for LLMs can fail and that prompt injections (including memory‑poisoning attacks) remain a risk. Users should be cautious with untrusted links and limit AI app access.

Rovo Flaw Lets Attackers Exfiltrate Jira/Confluence Data via Prompt Injection
security15 days ago

Rovo Flaw Lets Attackers Exfiltrate Jira/Confluence Data via Prompt Injection

Security researchers found that Atlassian's Rovo assistant can be tricked into sending Jira and Confluence data to attackers through attacker-controlled prompts and a malicious URL parameter. Two independent reports (PromptArmor and Varonis Threat Labs) detail a content-borne prompt injection path and a one-click link path, with Atlassian fixing the link-based flaw on July 8, 2026; the content-borne path’s status remained uncertain as of Aug 8, 2026. Exfiltration occurs within the victim’s signed-in permissions, and admins can mitigate by restricting Rovo usage by app/group or disabling Rovo features. No CVEs have been issued. Organizations should tighten app scopes and permissions rather than relying on the web-search toggle as a security boundary.

ClickLock: macOS malware coerces password entry to steal data and plant a backdoor
security1 month ago

ClickLock: macOS malware coerces password entry to steal data and plant a backdoor

A new macOS information-stealing malware named ClickLock uses social engineering and a fake Cloudflare verification to force users into typing their system login password, exfiltrates credentials, browser data and wallet information, and installs a persistent backdoor via two LaunchAgent components; it suppresses notifications, runs password-dialog loops for hours or days, and uploads stolen data through Telegram while maintaining persistence for weeks, with infections in 33 countries and at least 100 observed since May. Defenders are advised to avoid pasting unknown Terminal commands and to boot into Safe Mode if prompted for a password.

AI-Generated PowerShell Tool Maps Active Directory in Rapid Breach
security1 month ago

AI-Generated PowerShell Tool Maps Active Directory in Rapid Breach

Cybersecurity researchers flag a June 2026 intrusion where attackers used an AI-generated, vibe-coded PowerShell script to enumerate a Windows Active Directory after gaining RDP access to a domain-joined server. The tool locates the Domain Controller, maps AD users, computers, groups, OUs, and trusts, creates a staging area, and exports results (including AD_Report.html). Attackers then deployed s5cmd and SharpShares to locate data repositories, exported data to CSV, archived it, and exfiltrated it to a remote server. The incident highlights how AI-assisted tooling lowers entry barriers and accelerates reconnaissance, aligning with established smash-and-grab playbooks, while a related Sygnia report notes AI-enabled cloud intrusions can scale quickly using credentials and cloud weaknesses rather than new malware.

TrojPix Turns Screens Into Covert Transmitters for Air-Gapped PCs
technology1 month ago

TrojPix Turns Screens Into Covert Transmitters for Air-Gapped PCs

Researchers from Shandong University demonstrated TrojPix, a covert-channel that leaks data from air-gapped PCs by modulating on-screen pixels to emit a signal over video cables. In tests it achieved up to 8.1 Mbps throughput and up to 208 meters range (measured separately). It requires malware on the target but no admin rights or hardware changes, and uses two methods to hide the traffic: spoofing a dark display or embedding signals in visible content. It works across multiple monitor brands and cables, but real-world range will be affected by walls and shielding. Mitigations include using fiber-optic video, shielding, TEMPEST practices, and keeping malware off the machine. The work is currently lab-based and adds to a family of screen-based leakage techniques.

Three-stage flaw turns Copilot Enterprise into a one-click data thief
technology2 months ago

Three-stage flaw turns Copilot Enterprise into a one-click data thief

A three-stage vulnerability chain dubbed SearchLeak lets attackers exfiltrate sensitive data from a target’s Microsoft 365 Copilot Enterprise sources (mail, OneDrive, SharePoint) via a crafted Copilot Search URL. The chain combines a parameter-to-prompt injection, an HTML rendering race condition, and a CSP bypass enabled by Bing SSRF. When a victim clicks the link, Copilot performs the search and formats results into an image URL; the browser then requests that image through Bing, revealing the data to the attacker in the logs. Microsoft patched CVE-2026-42824 with a critical rating; no user action is required, but the incident highlights how prompt injection can weaponize legacy bugs in AI-enabled tools.

OpenAI Adds Lockdown Mode to ChatGPT to curb data exfiltration risks
technology2 months ago

OpenAI Adds Lockdown Mode to ChatGPT to curb data exfiltration risks

OpenAI is rolling out an optional Lockdown Mode for eligible ChatGPT users to reduce data exfiltration risk from prompt injections by restricting outbound web access and other capabilities (live web browsing, image display, network access, and file downloads); it complements existing safeguards, cannot be used with Developer Mode, and does not guarantee complete protection, with risk potentially remaining via apps or new techniques; the update also adds a separate account-management feature to review and log out active sessions.

GitHub breach tied to poisoned VS Code extension hits thousands of internal repos
security3 months ago

GitHub breach tied to poisoned VS Code extension hits thousands of internal repos

GitHub confirmed that a poisoned Visual Studio Code extension installed on an employee’s device led to the exfiltration of roughly 3,800 internal repositories; the malicious extension was removed from the VS Code Marketplace and the endpoint isolated, with incident response begun. Current assessment indicates only GitHub’s internal repositories were affected and there is no evidence that customer data outside the affected repos was compromised. The TeamPCP group has claimed access to about 4,000 repos on a cybercrime forum, though attribution remains unsettled. This follows a history of trojanized VS Code extensions used to steal code and credentials.

Batch of 108 Chrome extensions steals Google and Telegram data from about 20,000 users
technology4 months ago

Batch of 108 Chrome extensions steals Google and Telegram data from about 20,000 users

Researchers uncovered a campaign of 108 Chrome extensions that funnel user data to a shared command-and-control backend, stealing Google account credentials via OAuth2, exfiltrating Telegram sessions, stripping security headers, and injecting ads and arbitrary scripts across every page you visit, in a campaign affecting roughly 20,000 installs. The extensions masqueraded as Telegram clients, gaming tools, and video enhancers, making the backdoor hard to spot; users should remove these extensions and log out of Telegram Web immediately.

DarkSword: High-End iOS Exploit Kit Uses Zero-Days for Rapid Device Takeover
security5 months ago

DarkSword: High-End iOS Exploit Kit Uses Zero-Days for Rapid Device Takeover

DarkSword is a JavaScript-based iOS exploit kit targeting iPhones on iOS 18.4–18.7 via watering-hole campaigns, chaining six vulnerabilities to achieve remote code execution, escaping the WebContent sandbox through the GPU into mediaplaybackd, escalating to kernel privileges, and then loading a data-collection module to exfiltrate a wide range of information (including emails, iCloud data, messages, wallet data, photos, contacts, and more) before cleaning up. Used by UNC6353 and linked groups such as UNC6748 and PARS Defense, the kit underscores a growing market for high-end iOS exploits and rapid, non-persistent data theft.

OpenClaw Under Fire: Prompt Injection and Data Leakage Risks
security5 months ago

OpenClaw Under Fire: Prompt Injection and Data Leakage Risks

CNCERT warns that OpenClaw’s weak default security and privileged execution could enable prompt-injection attacks, including indirect prompt injection via web content and link previews that leak sensitive data; other risks include misinterpretation causing data loss, uploading malicious skills to repositories like ClawHub, and exploiting known vulnerabilities. China is restricting OpenClaw in state entities, while attackers distribute malware via GitHub rep o s posing as OpenClaw installers. Mitigations include hardening networks, isolating the service, avoiding plaintext credentials, downloading skills only from trusted sources, disabling automatic updates, and keeping the agent up to date.

Cloud breaches pivot to new flaws as credential abuse wanes
technology5 months ago

Cloud breaches pivot to new flaws as credential abuse wanes

Google’s threat intelligence shows cloud intrusions are increasingly driven by exploiting freshly disclosed third-party software flaws, shrinking the window to weaponize exploits to days. Weak credentials have declined as an attack vector while remote code execution flaws like React2Shell (CVE-2025-55182) and XWiki (CVE-2025-24893) are frequently exploited. Attacks often begin via phishing or stolen identities, with Iran-, China-, and North Korea–linked campaigns maintaining long-term access to steal data, crypto, and credentials. OpenID Connect abuse, supply-chain incidents, and insider threats also feature prominently, underscoring the need for automated, rapid incident response as cloud threats accelerate into 2026.

BeyondTrust Flaw Sparks Global Web Shell Campaigns and Data Theft
security6 months ago

BeyondTrust Flaw Sparks Global Web Shell Campaigns and Data Theft

Threat actors are exploiting CVE-2026-1731 in BeyondTrust RS/PRA to run OS commands, deploy web shells and backdoors, establish C2, and exfiltrate data across sectors worldwide. Unit 42 reports use of a thin-scc-wrapper via WebSocket to execute commands in the site user context, effectively taking control of appliances and traffic. Campaigns include PHP backdoors, VShell, a bash dropper, and Spark RAT, with staged exfiltration of config files, internal databases, and PostgreSQL dumps. The activity aligns with prior CVE-2024-12356 issues, and CISA KEV confirms exploitation in ransomware operations.

Coordinated Chrome Extensions Hijack Affiliate Links and Loot ChatGPT Tokens
technology6 months ago

Coordinated Chrome Extensions Hijack Affiliate Links and Loot ChatGPT Tokens

Security researchers uncovered a coordinated campaign of 29 Chrome extensions that covertly inject affiliate tags into product URLs on major retailers (Amazon, AliExpress, Best Buy, Shein, Shopify, Walmart), siphoning commissions and scraping data; a separate set of 16 extensions targets ChatGPT by injecting scripts into chatgpt.com to steal authentication tokens, enabling access to user conversations and data. The findings also reference a malware-as-a-service kit called Stanley that could help attackers generate extensions capable of bypassing Google’s vetting, highlighting the growing risk of malicious browser extensions as an attack surface.