North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure.
Category: eSecurity Planet
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical Orkes Conductor flaw is under active attack, with 6,696 exploit attempts blocked in a week. Defenders should upgrade to version 3.30.2 or later.
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure.
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical Orkes Conductor flaw is under active attack, with 6,696 exploit attempts blocked in a week. Defenders should upgrade to version 3.30.2 or later.
Malicious HEIF Upload Reached OpenAI’s Internal GitHub, Researchers Reveal
A malicious HEIF upload exploited Discourse, crossed OpenAI’s identity layer, and reached an internal GitHub repo through a connected Codex account.
HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users.
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
Weekly summary of Cybersecurity Insider newsletters
36,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring.
CISA Warns Attackers Are Exploiting Acronis Backup Flaw on Linux Servers
CISA added CVE-2026-87886 to its KEV catalog after confirmed exploitation of an Acronis Backup flaw affecting Linux hosting environments.
Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access.
1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
Attackers scanned 1.8 million Android APKs for hardcoded secrets, showing why developers need stronger credential management and production-build security.
Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs
Iranian state-linked attackers are using fake MRI scans and software lures to deploy CHOSEN BRICK spyware on Windows PCs.
HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users.
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
36,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring.
Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks
Cisco Talos says attackers are exploiting FMC flaws to steal credentials, tunnel into internal networks, and deploy Qilin ransomware.
CISA Warns of Active GitLab Exploitation as Attackers Target Server Files
CISA warns attackers are exploiting a critical GitLab flaw that exposes server files, credentials and development pipelines. Learn how to respond.
Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access.
1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
Attackers scanned 1.8 million Android APKs for hardcoded secrets, showing why developers need stronger credential management and production-build security.
