Cybersecurity

550K Veeam Backdoors: 17-Month Ransomware Binge Ends—Fortune 500 Forks the Bill

Cybersecurity

550K Veeam Backdoors: 17-Month Ransomware Binge Ends—Fortune 500 Forks the Bill

TL;DR * Veeam Backup & Replication patched four critical RCE vulnerabilities (CVE-2026-21666, CVE-2025-21668, CVE-2027-21708) enabling privilege escalation and SSH theft * Erlang OTP 28.4.1 patches critical SSH compression and HTTP request vulnerabilities * SocksEscort Botnet Dismantled: 8,000 Infected Routers Seized Across 2,500 US Homes 💥 550K Veeam Backdoors Shut:

By Barista @ Cafecito
OK Bot Hacks Dutch Gov: 30+ Accounts Compromised — SMS 2FA Still Alive in 2026

Cybersecurity

OK Bot Hacks Dutch Gov: 30+ Accounts Compromised — SMS 2FA Still Alive in 2026

TL;DR * Russian state-sponsored hackers compromise WhatsApp and Signal accounts via phishing authentication codes * Cybercriminals exploit misconfigured Salesforce Experience Cloud sites using customized AuraInspector tool to harvest data for social engineering * ScamAgent AI framework developed at Rutgers University bypasses safety guardrails to simulate realistic social engineering attacks 🤖 30+ Gov Accounts

By Barista @ Cafecito
Revoked Certificates Still Trusted: 2.4M Windows Systems Compromised — Microsoft Defender Fails Trust Chain — Enterprise Security Crisis

Cybersecurity

Revoked Certificates Still Trusted: 2.4M Windows Systems Compromised — Microsoft Defender Fails Trust Chain — Enterprise Security Crisis

TL;DR * Microsoft Defender identifies phishing campaign using ScreenConnect, Tactical RMM, and Mesh Agent via signed MSI packages in February 2026 * Phishing campaign impersonates Zoom and Google Meet waiting rooms to deploy Windows remote monitoring malware * Trail of Bits releases mquire, a Linux memory forensics tool that analyzes dumps without

By Barista @ Cafecito
💣 581 CVEs Per Codebase: Global Supply Chain Security Collapses as Two-Thirds of Enterprises Face Active Compromise

Cybersecurity

💣 581 CVEs Per Codebase: Global Supply Chain Security Collapses as Two-Thirds of Enterprises Face Active Compromise

TL;DR * Open source dependency vulnerabilities double: median CVEs per codebase rises from 280 to 581, 65% suffer supply chain attacks * Cortex XDR Live Terminal vulnerability (CVE-2026-0323-2400) allows cross-tenant C2 redirection via WebSocket hijack * Remington.bg breached, exposing 150,000+ customer and order records in Bulgaria cyber incident 💣 581 CVEs

By Barista @ Cafecito