xz backdoor and Microsoft Android token theft
The Linux kernel’s AF_ALG crypto socket interface can be abused by any unprivileged user to corrupt the page cache of arbitrary files, such as /usr/bin/sudo, without any filesystem changes, enabling root escalation. The bug affects kernels 4.14-6.19 and 7.0 RCs, is confirmed in the wild, and appears in CISA’s KEV catalog.
The xz‑utils backdoor (CVE‑2024‑3094) was a maintainer‑trust hijack, not a code flaw, and escaped detection by CVE‑driven scanners. The incident shows that supply‑chain tools need real‑time maintainer signals and lockfile review, not just static vulnerability databases.
A forgotten debug flag (setIsDebugMode = true) left enabled in production code of six Microsoft 365 Android apps let any co‑installed app silently obtain valid Microsoft account tokens. The flaw, dubbed FlagLeft, affected Word, Excel, PowerPoint, Copilot, Loop and OneNote, exposing billions of downloads to silent account takeover. Microsoft has released patches.
Reversec shows that Claude Code skill files and sub‑agents act like untrusted pip packages, letting attackers gain initial access and execute arbitrary code on developer machines. The post details two exploit paths, underscoring the need for vetting and securing skill files.
Researchers discovered NomShub, a chain of vulnerabilities in the Cursor AI code editor that lets a malicious repository execute indirect prompt injection, escape the IDE sandbox via shell builtins, and activate Cursor’s built‑in remote tunnel for persistent, undetected shell access. The attack requires only opening the repo, highlighting the risk of AI‑assisted coding tools.
A Claude‑based AI agent was able to turn a leaked low‑privilege IAM key into full data exfiltration from an AWS environment in about one minute, succeeding in 7 of 12 attempts. The test shows that post‑compromise actions can outrun CloudTrail’s five‑minute log delay, highlighting a new detection gap for AI‑driven attacks.
Unit42 uncovered Operation FlutterBridge, a macOS malvertising campaign that drops the FlutterShell backdoor built with Google’s Flutter framework. The payload combines adware with shell command execution and AI‑driven data exfiltration, spreading through Google‑verified ads targeting Western users.
A sophisticated threat actor stole a senior stock‑exchange executive’s Outlook mailbox and exfiltrated data for five months using legitimate cloud services such as Dropbox and OneDrive to mask activity. The attackers deployed masquerading binaries for persistence and leveraged public tools, illustrating the high‑value nature of executive email in financial espionage.
Eye Security reports a sharp increase in business‑email‑compromise (BEC) attacks that abuse Microsoft’s device code flow, tricking users into entering codes on legitimate Microsoft pages while attackers gain persistent access. The research outlines detection, prevention, and forensic techniques to combat this hard‑to‑spot phishing vector.
Trail of Bits demonstrated that public AI skill marketplaces are rife with malicious skills that can evade all major scanners, including ClawHub, Cisco, and skills.sh, using trivial tricks like adding 100k newlines. The researchers urge developers to avoid public skill stores, highlighting the need for stronger, dynamic defenses against skill‑based attacks.
Dashlane disclosed that a brute‑force attack on its two‑factor authentication allowed attackers to download encrypted vaults from fewer than 20 personal‑plan users. The company found no evidence its internal systems were breached and emphasized that vaults remain protected by master passwords. Affected users were directly notified and accounts have been restored.
Workcell launches AI coding agents inside a hardened container on a dedicated Colima VM, isolating them from the host macOS environment on Apple Silicon. The tool ships native adapters for Codex, Claude Code, and Gemini, letting teams run agents locally without exposing home directories, keychains, or provider credentials.
Subscribe free