LODESubscribe →

Next.js Zero‑Click, Zapier Chain, Ransomware IT Scam

Infosec · 2026-06-06

Vulnerabilities & Exploits
Zero‑click SXSS via header reflection in Next.js cache9 MIN

Researchers discovered that mirroring request headers into response headers enables a reliable zero‑click cross‑site scripting attack on recent Next.js versions. By forcing the App Router to treat a request as HTML, attackers can inject payloads through reflected URL parameters, bypassing typical defenses.

Zapocalypse: Five‑Step Chain That Could Have Hijacked Zapier17 MIN

Token Security uncovered a five‑step attack chain—dubbed “Zapocalypse”—that could have let an adversary publish malicious JavaScript to every authenticated Zapier user’s browser, achieving full account takeover. Zapier patched the flaw within weeks and revoked the compromised NPM token, highlighting supply‑chain risks in SaaS automation platforms.

Open‑Weight LLMs Replicate Anthropic Mythos FreeBSD RCE Discovery for Under $10014 MIN

Using the same three‑stage nano‑analyzer pipeline that AIS LE used with GPT‑5.4‑nano, the author runs open‑weight models (GPT‑OSS‑20B and Gemma‑4‑31B‑IT) on the full FreeBSD RPCSEC_GSS codebase and, after a simple reachability tweak, successfully flags the 17‑year‑old CVE‑2026‑4747 RCE. The experiment shows that modest, locally run models can duplicate frontier‑model zero‑day detection when supported by effective scaffolding.

Depthfirst AI Agent Uncovers 21 New Zero-Day Bugs in FFmpeg13 MIN

Depthfirst’s autonomous security agent has identified 21 previously unknown zero‑day vulnerabilities in the widely used FFmpeg library, many of which had been lurking for 15‑20 years. The findings include reproducible proof‑of‑concept exploits, underscoring AI’s growing ability to uncover deep, critical bugs in complex codebases.

Threats & Malware
Magecart Skimmer Hijacks Stripe as Hidden Command‑and‑Control Server7 MIN

Security researchers discovered a Magecart skimmer that stores malicious code in a Stripe customer's metadata and executes it via Google Tag Manager on checkout pages. The stolen card data is exfiltrated back to the attacker’s Stripe account as fake customers, letting the fraud blend into trusted traffic and bypass CSPs.

Ransomware gang pretends to be IT staff to breach law firms2 MIN

Google and the FBI report that the Silent Ransom Group is dispatching impostor IT workers to law firms, using USB drives or remote tools to steal contracts, personal data, and financial records. The gang then threatens to publish the stolen information unless a ransom is paid, expanding the physical‑social engineering angle of ransomware attacks.

ESET uncovers Android spyware 'Asin' targeting Arabic journalists with fake news apps1 MIN

ESET discovered a new Android spyware family called Asin that has been distributed since early 2025 through malicious apps masquerading as government news, PDF readers and war‑map tools aimed at Arabic‑speaking users. The campaigns appear to target journalists and OSINT researchers, tricking victims into manually installing the apps and granting spyware permissions.

Miasma worm spreads via npm, forces GitHub to disable 73 Microsoft repos14 MIN

Microsoft’s Threat Intelligence team uncovered the Miasma supply‑chain campaign, where malicious npm packages under the @redhat‑cloud‑services scope injected a pre‑install hook that hijacked developer credentials and propagated to 73 GitHub repositories across Azure, Azure‑Samples, Microsoft and MicrosoftDocs. GitHub responded by disabling the affected repos within minutes, highlighting the rapid spread of the self‑replicating worm.

Breaches & Industry News
Weil Gotshal pays up to $20 million to halt ransomware threat1 MIN

US law firm Weil Gotshal & Manges reportedly paid between $18 million and $20 million to the Luna Moth ransomware group to prevent the public release of stolen client documents. The firm activated response protocols, engaged third‑party security experts, and notified law enforcement, but says the attackers never accessed its internal network.

ShinyHunters leaks 234 GB of DentaQuest data, exposing 2.6 M accounts2 MIN

DentaQuest confirmed a ransomware breach by ShinyHunters after ransom negotiations failed. The gang leaked about 234 GB of data, revealing personal, insurance and ID details for 2.6 million individuals. The company says operations continue and investigators are assessing the impact.

Columbia University breach exposes 1.8 M SSNs, even those never applied1 MIN

In 2025, Columbia University suffered a hack that exfiltrated about 460 GB of data, leaking roughly 1.8 million Social Security numbers from decades‑old recruitment and testing records. The leak includes individuals who never applied to the school. Columbia is offering two years of free credit monitoring and identity restoration services to affected persons.

Privacy, Policy & Governance
OpenAI adds Lockdown Mode to ChatGPT, disabling web browsing and tools to curb data exfiltration7 MIN

OpenAI's new Lockdown Mode is an optional security setting that blocks live web browsing, image fetching, Deep Research, Agent Mode, Canvas networking, and file downloads. By limiting outbound network requests, it aims to reduce data exfiltration risk from prompt‑injection attacks for users handling sensitive information.

Supreme Court Upholds FCC Fines Over Telecoms' Sale of Location Data4 MIN

In an 8‑1 decision, the U.S. Supreme Court rejected AT&T and Verizon's challenge to FCC penalties totaling $100 million for unlawfully sharing customer location data with third parties. The ruling preserves the FCC’s authority to enforce data‑privacy rules on telecom carriers.

Smart TVs Turned Into Residential Proxies Power AI Data Scraping13 MIN

Include Security reveals Bright Data’s consent‑SDK embeds in smart TV apps, converting them into exit nodes for residential proxy networks. This lets AI firms bypass cloud‑IP blocks and harvest web data at scale, raising privacy concerns for everyday consumers.

Google Wallet to Become EU’s Central Age‑Verification ID Hub3 MIN

Google will store government‑issued digital IDs in Google Wallet for select EU nations, allowing its service to verify users’ age on websites. This shifts age‑gate data from sites to Google, giving the company unprecedented insight into identity checks and sparking privacy concerns over a private ID verifier.

Research & Tools
WasmForge converts Sliver C2 into WebAssembly binaries for stealthy red‑team implants16 MIN

Praetorian’s new WasmForge tool wraps existing offensive security binaries—like the Sliver C2 framework—into WebAssembly‑based executables that evade EDR signatures without source changes. By compiling Go projects to wasm32, adding custom host shims, and obfuscating binaries, it lets red‑team operators drop stealthy implants on hardened endpoints.

Effective harnesses narrow bug-finding gap for open-weight models18 MIN

The author compares several open-weight LLMs (DeepSeek V4, Qwen3.5, Kimi, GLM-5/5.1) against the closed-source Opus 4.7 on the crackaddr vulnerability suite. While open models lag on tougher artifacts, a well-designed harness and post-training tweaks close most of the gap, with GLM-5.1 matching Opus performance.

Z‑Jail delivers a zero‑dependency, multi‑layer Linux sandbox for native code10 MIN

Z‑Jail is a ~130 KB, single‑binary sandbox for Linux that layers seven hardening mechanisms—namespaces, pivot_root, capability drops, no‑new‑privs, seccomp‑BPF whitelist, audit logging, and more—without any external dependencies. It targets CI pipelines, CTF challenges, and lightweight code evaluation where full VM isolation is overkill.

Get Infosec in your inbox, every issue.
Subscribe free
🎧 Listen: RSS
Podcasts
Privacy · Terms · About · Contact
© 2026 LODE