LodeHQSubscribe →

xz backdoor and Microsoft Android token theft

Infosec · 2026-06-04

Vulnerabilities & Exploits
Copy Fail (CVE‑2026‑31431) Enables Unprivileged Page‑Cache Corruption for Root Escalation11 MIN

The Linux kernel’s AF_ALG crypto socket interface can be abused by any unprivileged user to corrupt the page cache of arbitrary files, such as /usr/bin/sudo, without any filesystem changes, enabling root escalation. The bug affects kernels 4.14-6.19 and 7.0 RCs, is confirmed in the wild, and appears in CISA’s KEV catalog.

xz‑utils backdoor exposes limits of CVE‑driven supply‑chain scanners8 MIN

The xz‑utils backdoor (CVE‑2024‑3094) was a maintainer‑trust hijack, not a code flaw, and escaped detection by CVE‑driven scanners. The incident shows that supply‑chain tools need real‑time maintainer signals and lockfile review, not just static vulnerability databases.

Debug Flag Left in Microsoft Android Apps Exposes Billions to Token Theft5 MIN

A forgotten debug flag (setIsDebugMode = true) left enabled in production code of six Microsoft 365 Android apps let any co‑installed app silently obtain valid Microsoft account tokens. The flaw, dubbed FlagLeft, affected Word, Excel, PowerPoint, Copilot, Loop and OneNote, exposing billions of downloads to silent account takeover. Microsoft has released patches.

Claude Code skill files can serve as stealthy initial‑access vectors25 MIN

Reversec shows that Claude Code skill files and sub‑agents act like untrusted pip packages, letting attackers gain initial access and execute arbitrary code on developer machines. The post details two exploit paths, underscoring the need for vetting and securing skill files.

NomShub Exploits Cursor’s Remote Tunnel to Hijack Developer Machines35 MIN

Researchers discovered NomShub, a chain of vulnerabilities in the Cursor AI code editor that lets a malicious repository execute indirect prompt injection, escape the IDE sandbox via shell builtins, and activate Cursor’s built‑in remote tunnel for persistent, undetected shell access. The attack requires only opening the repo, highlighting the risk of AI‑assisted coding tools.

LLM Agent exfiltrates AWS data in 60 seconds using leaked IAM key7 MIN

A Claude‑based AI agent was able to turn a leaked low‑privilege IAM key into full data exfiltration from an AWS environment in about one minute, succeeding in 7 of 12 attempts. The test shows that post‑compromise actions can outrun CloudTrail’s five‑minute log delay, highlighting a new detection gap for AI‑driven attacks.

Threats & Malware
Operation FlutterBridge Deploys FlutterShell Backdoor via macOS Malvertising22 MIN

Unit42 uncovered Operation FlutterBridge, a macOS malvertising campaign that drops the FlutterShell backdoor built with Google’s Flutter framework. The payload combines adware with shell command execution and AI‑driven data exfiltration, spreading through Google‑verified ads targeting Western users.

Five‑Month Espionage Campaign Hijacked Stock Exchange Executive’s Email via Cloud‑Based Exfiltration7 MIN

A sophisticated threat actor stole a senior stock‑exchange executive’s Outlook mailbox and exfiltrated data for five months using legitimate cloud services such as Dropbox and OneDrive to mask activity. The attackers deployed masquerading binaries for persistence and leveraged public tools, illustrating the high‑value nature of executive email in financial espionage.

Surge in BEC Attacks Leveraging Microsoft Device Code Phishing11 MIN

Eye Security reports a sharp increase in business‑email‑compromise (BEC) attacks that abuse Microsoft’s device code flow, tricking users into entering codes on legitimate Microsoft pages while attackers gain persistent access. The research outlines detection, prevention, and forensic techniques to combat this hard‑to‑spot phishing vector.

AI Skill Scanners Bypassed by Simple Tricks, Trail of Bits Finds10 MIN

Trail of Bits demonstrated that public AI skill marketplaces are rife with malicious skills that can evade all major scanners, including ClawHub, Cisco, and skills.sh, using trivial tricks like adding 100k newlines. The researchers urge developers to avoid public skill stores, highlighting the need for stronger, dynamic defenses against skill‑based attacks.

Breaches & Industry News
Dashlane reveals brute‑force attack that stole under 20 encrypted vaults3 MIN

Dashlane disclosed that a brute‑force attack on its two‑factor authentication allowed attackers to download encrypted vaults from fewer than 20 personal‑plan users. The company found no evidence its internal systems were breached and emphasized that vaults remain protected by master passwords. Affected users were directly notified and accounts have been restored.

Research & Tools
Workcell Enables Secure, Local AI Coding Agents on Apple Silicon12 MIN

Workcell launches AI coding agents inside a hardened container on a dedicated Colima VM, isolating them from the host macOS environment on Apple Silicon. The tool ships native adapters for Codex, Claude Code, and Gemini, letting teams run agents locally without exposing home directories, keychains, or provider credentials.

Get Infosec in your inbox, every issue.
Subscribe free
Privacy · Terms · About · Contact
© 2026 LodeHQ