2849 stories
·
0 followers

Hackers stole Pentagon personnel records of over 3 million people

1 Share
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. [...]
Read the whole story
NerdsToGo
23 hours ago
reply
Share this story
Delete

Critical TeamViewer Vulnerabilities Enable Remote Code Execution and Privilege Escalation Attacks

1 Share

TeamViewer has released security updates for five high-severity vulnerabilities in its remote-access software that could enable remote code execution, local privilege escalation, arbitrary file writes, and bypasses of user-configured session permissions.

The flaws, tracked under bulletin TV-2026-1010, affect TeamViewer Full Client and Host installations across Windows, Linux, and macOS, with the most severe issue carrying a CVSS score of 8.8.

The company said it addressed the vulnerabilities in TeamViewer version 15.82 and corresponding supported maintenance and legacy releases. TeamViewer is not aware of public disclosure or active exploitation of the flaws in the wild at the time of the September 29, 2026 advisory.

Critical TeamViewer Vulnerabilities

The highest-rated vulnerability, CVE-2026-92370, is an improper access control issue affecting TeamViewer Full Client, Host, and related modules prior to version 15.82 on Windows, Linux, and macOS. It received a CVSS score of 8.8.

An authenticated remote attacker could allegedly manipulate access-control parameters during session establishment to bypass restrictions explicitly configured by the target user.

This could allow the attacker to perform unauthorized session actions that were intended to be blocked, potentially leading to remote code execution on the affected device.

Because TeamViewer is commonly deployed for help-desk support, unattended device management, and enterprise remote administration, a permission-bypass flaw could create significant risk where attackers gain or abuse remote-session access.

Organizations should review TeamViewer permission profiles and audit recent session activity while applying the update.

CVE-2026-19743 is a path traversal vulnerability in TeamViewer’s local IPC service. It affects Full Client and Host deployments before version 15.82 across Windows, Linux, and macOS, and has a CVSS score of 7.8.

A locally authenticated, low-privileged attacker could send crafted IPC commands to the TeamViewer service daemon and abuse insufficient path validation.

Successful exploitation could permit arbitrary file writes with elevated permissions, including NT AUTHORITY\SYSTEM on Windows or root on Linux and macOS, resulting in local privilege escalation.

Two other vulnerabilities also create elevation-of-privilege risks. CVE-2026-92369 is a Windows installer rollback race condition.

A local attacker could replace rollback backup files in a user-writable temporary directory before an elevated installer restores them, potentially obtaining SYSTEM privileges. Exploitation requires a successful race condition during installation or an update rollback.

CVE-2026-92371 affects Linux Cloud Session Recording functionality. The flaw stems from improper link resolution and a race condition between path validation and file access, enabling a local authenticated attacker to redirect privileged file operations to unintended locations.

TeamViewer also patched CVE-2026-92368, a heap-based buffer overflow in the handling of .tvs session-recording files on Linux and macOS. The vulnerability arises from a size mismatch during decompression of recorded session data.

An attacker could craft a malicious recording file and persuade a victim to open it through TeamViewer’s “Play or convert recorded session” feature. If successful, the flaw could cause out-of-bounds heap writes and enable arbitrary code execution with the logged-in user’s privileges.

Administrators should treat unsolicited .tvs files as potentially malicious, particularly on endpoints that have not yet been updated.

Endpoint-monitoring teams should also investigate unusual TeamViewer recording playback activity, unexpected installer rollbacks, and suspicious file writes involving TeamViewer service processes.

Organizations should update TeamViewer Full Client and Host installations to version 15.82 or later immediately. This includes Windows, Linux, and macOS systems, as well as TeamViewer Remote, TeamViewer Tensor, and TeamViewer ONE environments using affected client components.

Supported older branches have also received fixes, including version 15.64.8 for Windows 7 and Windows 8, version 14.7.48855, and version 13.2.36230 or related platform-specific releases.

Security teams should inventory unmanaged endpoints and confirm that remote-access tooling is updated consistently, since TeamViewer deployments often span employee workstations, servers, third-party support systems, and unattended devices.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 

The post Critical TeamViewer Vulnerabilities Enable Remote Code Execution and Privilege Escalation Attacks appeared first on Cyber Security News.



Read the whole story
NerdsToGo
23 hours ago
reply
Share this story
Delete

FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum

1 Share
  • 153 million US driving licences have been leaked on a Russian cybercrime platform
  • Among those apaprently discovered in the stolen data is US Secretary of Defense Pete Hegseth
  • The FBI is now investigating the leak, which has been traced to an identity verification company

A data leak of 153 million US drivers licenses is said to have been shared on a Russian cybercrime forum, with US Secretary of Defense Pete Hegseth among those leaked prompting an FBI investigation.

Security researcher Brian Krebs identified the leak – which included his own data – as originating from a hack of an identity verification service. Louisiana-based IDScan provided ID verification for various well-known companies, including FedEx and Hertz car hire.

The data was shared on a Russian forum called Exploit, a long-established online community of cybercriminals. Following news of the leak, the identity theft service “Nexus” has apparently scrubbed its existence from the Dark Web.

Driving licenses and more

It wasn’t just US driving licenses that were found in the archive of recently-collected personal data. Krebs’ investigation found that Nexus claimed other types of data, and found a further 1.1 million driving licenses from Canada.

Other identity documentation alleged to be in the leak include 10 million identification cards, three million travel documents and international IDs, and 579,000 medical cards. The data was available to browse, notes Krebs, with Nexus providing details: “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

The leak has a personal dimension for Krebs. Not only was his driving license in the collection, so was that of his mother. It has proved to be a useful coincidence, one that has enabled the security and privacy researcher to establish how the data was sourced by Nexus.

Both licenses were used for a car hire, which Krebs traced to Hertz. Others affected by the leak had also used the service, which has used New Orleans-based IDscan for identity verification.

The company, which claims to perform 21 million verifications a month, is yet to issue a statement on the matter. Its marketing and operations leader, Jillian Kossman, told the journalist: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.”

Where is the data?

Krebs reports that he was alerted to the data on August 31, 2026, little over a week ago. Regular checking noted that the data was still being added to, increasing by “nearly 400,000” records prior to publishing his investigation on September 1.

Since then, however, it seems that Nexus has vanished, along with the data. But how widely was the data downloaded before that happened? While the FBI investigates, it falls on the American and Canadian public to be extra vigilant and wary of identity fraud.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Almost 8000 organizations hit by fake voicemail transcript emails in credential phishing attack

1 Share
  • Check Point spotted phishing emails spoofing voicemail transcript notifications, hitting 7,800+ orgs
  • Malicious SVG attachments auto‑fill victim emails, redirecting to fake login pages for credential theft
  • SVG format bypasses filters; businesses urged to verify notifications and treat SVGs as active content

Hackers have a new phishing lure - the automated voicemail transcript notification, and have already used it against thousands of organizations already, sending tens of thousands of malicious emails.

In a new report, security experts from Check Point Research (CPR) said they spotted an ongoing campaign that has already targeted thousands of organizations.

The goal of the campaign seems to be credential theft - grabbing access to people’s email accounts, business services, and similar.

The proliferation of AI gave rise to a new trend in the office - automated voicemail transcripts. When a person receives a voicemail, they can choose to read it instead of listening to it. Useful for a noisy workplace environment, or for emails that are too sensitive to be blasted through a speaker system. An automated system mails the transcript to the recipient’s inbox in a familiar format, and since they’re used to receiving this type of email, they’re not suspicious or skeptical enough. Their guard is lowered, which is a perfect opportunity for the attackers.

“Between August 17 and August 31, Check Point identified more than 58,000 emails tied to the campaign. The operation targeted over 7,800 organizations, leveraging more than 38,400 spoofed sender addresses across over 9,300 spoofed domains,” the researchers explained.

The emails follow a simple formula the recipients are already used to seeing. Each message’s subject line begins with “Automated transcript”, followed by a partially redacted phone number and a random tracking string. “The effect is deliberately understated: a notification that appears to have been generated by a trusted workplace system,” CPR explains.

The email domains are also spoofed in a way that makes it seem as if they’re coming from within the same organization.

SVG attachments

Every email comes with an attachment. It is designed to look like a regular call recording file, using names such as “▷ ——— 001min 09sec_….svg.” But notice the file type - SVG. This is not an audio file, it is short for Scalable Vector Graphics (SVG) - an image file. There are a few reasons why scammers are opting for this particular format, but the number one is that it is an XML-based document that can contain JavaScript. When a browser opens the SVG, that JavaScript can execute, redirecting victims to a spoofed login page where they’re asked to log in.

This is exactly the setup here, too. To make matters worse, since the recipient’s email address is hardcoded in the URL, the fake login form auto-fills it. When the victim opens up the SVG, they’re redirected to a login page where the “username” part is already populated, making it more personalized and credible.

Another key reason why SVG is a popular format in these attacks is that it can bypass email security systems. If scammers put a hyperlink in the email’s body, it can be scanned by the system, and sanitized if proven malicious (which it would). But without a link the only other thing a security system can check are the attachments, and there the usual suspects are .exe, .docx, or .pdf files. Very few are focusing on SVG files, as well.

Adapting to change

This campaign is a great example of how quickly attackers adapt to enterprise workflows as automation becomes more common, Check Point’s researchers have warned. In response, businesses should start treating automated notifications as signals that need to be verified - especially those when the sender appears to match the recipient’s domain.

Furthermore, businesses should define which file types and domains AI agents are allowed to access without human confirmation, and finally, they should definitely inspect SVG attachments as active content, not simply as images.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Fake Minecraft Mod Steals Passwords and Gives Hackers Remote Control of PCs

1 Share

Cybersecurity researchers have uncovered a fake Minecraft optimisation mod that steals browser passwords, payment-card data, cookies, Discord information, and system details while giving attackers remote control over infected Windows PCs.

The malicious Java Archive (JAR) pretends to be Lithium Extras 0.15.0+mc1.21.1, a companion mod for the legitimate CaffeineMC Lithium performance mod.

It appears convincing because 12 of its 13 modules perform real optimisation functions, including memory trimming and entity culling. However, a hidden module silently starts the malware infection chain.

After an eight-second delay, the fake mod checks the victim’s geolocation, collects the computer name, and downloads a 169 MB executable to %APPDATA%\Microsoft\Windows\javaw.exe.

The filename and folder are designed to look harmless on systems where Minecraft players commonly use Java. The downloaded file is disguised as a Node.js executable called DiscordNitroGenerator.exe.

It carries a private Java runtime and the final payload, Myth Stealer 3.2-FIX. This approach lets the malware run even if Java is not installed on the victim’s computer.

At the time the samples were submitted, both the malicious JAR and the second-stage executable had zero detections on VirusTotal.

Fake Minecraft Mod Backdoor

Before launching the final payload, the malware displays a fake administrator message asking users to approve a Windows User Account Control (UAC) prompt. The dialog uses a dark title bar and system-like wording to appear legitimate.

If the victim accepts, Myth Stealer gains higher privileges and begins collecting sensitive data. The malware can steal:

  • Saved passwords, cookies, browsing history, and payment cards from Chromium- and Firefox-based browsers
  • Discord tokens and chat-related data through Discord injection features
  • Clipboard content, screenshots, webcam images, and selected files
  • Hardware details, including BIOS serial numbers, motherboard data, CPU, GPU, and device UUIDs
  • Installed apps, drivers, running processes, network connections, and antivirus details
The token check behind its is_admin export (Source: medium)
The token check behind its is_admin export (Source: medium)

The payload sends stolen information through Discord webhooks and attacker-controlled command-and-control servers.

Researchers identified an IP-based server at 146[.]19[.]191[.]11 and a backup typosquatted domain, ays[.]gamepazarin[.]com, impersonating the Turkish game marketplace GamePazari.

A string literal resolved as a dynamic constant through its per-class decryptor (Source: medium)
A string literal resolved as a dynamic constant through its per-class decryptor (Source: medium)

Myth Stealer is more than an information stealer. It includes remote access capabilities that allow attackers to execute PowerShell commands, download and run additional files, delete data, search directories, and maintain startup persistence.

The tool also includes defence-evasion functions such as AMSI bypass, ETW patching, process hollowing, fileless execution, virtual-machine checks, and debugger detection, medium said.

Notably, it contains a harassment command set that can disrupt victims by moving the mouse, disabling the keyboard, shaking or rotating the screen, hiding the taskbar, changing wallpaper, displaying random pop-ups, inverting colours, and replacing cursor icons.

It can also show fake Windows Update and DirectX error screens to confuse users and hide malicious activity.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

The post Fake Minecraft Mod Steals Passwords and Gives Hackers Remote Control of PCs appeared first on Cyber Security News.



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete

Apple patches CoreGraphics zero-day used in 'extremely sophisticated' targeted attacks on iOS devices

1 Share
  • Apple patches high-severity CoreGraphics zero-day reportedly exploited against specific targeted individuals
  • The vulnerability enables arbitrary code execution through maliciously crafted files on affected Apple devices
  • Apple urged users to install the latest security updates, particularly high-value targets facing sophisticated attacks

Apple has released a fix for a zero-day vulnerability it says was allegedly used “in an extremely sophisticated attack against specific targeted individuals”.

The vulnerability was found in iOS 26.7.1 and iPadOS 26.7.1 and users are advised to apply the fix as soon as possible. This is particularly important for high-value targets such as diplomats, dissidents, whistleblowers, political opposition, and journalists.

Zero-day

The vulnerability was found in CoreGraphics, the company’s low-level 2D graphics framework used across different platforms (iOS, iPadOS, macOS, and more). CoreGraphics provides developers with tools they need to draw and render visual elements (lines, shapes, images, and even text), and can handle operations such as colors, transparency, gradients, clipping, etc. It is usually used when developers need more precise control over how something is drawn.

The vulnerability is tracked as CVE-2026-86950, with a severity score of 8.8/10 (high). The National Vulnerability Database (NVD) describes it as an out-of-bounds issue that allows threat actors to execute arbitrary code via a maliciously crafted file. The bug can also be exploited to crash programs and corrupt data. Besides iOS and iPadOS, it was also fixed in macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1.

Here is the full list of affected devices:

iPhone 11 and later

iPad Pro 12.9-inch 3rd generation and later

iPad Pro 11-inch 1st generation and later

iPad Air 3rd generation and later

iPad 8th generation and later

iPad mini 5th generation and later

Mac devices running macOS Sequoia 15.8.1 and Tahoe 26.7.1

Apple fixed it with improved bounds checking, it was said in the security advisory.

Abused in “extremely sophisticated” attacks

What makes this vulnerability stand out in a sea of zero-days is how Apple described observed exploitation attempts.

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” We don’t know which report Apple is referring to here - we could not find anyone discussing it. The company only said the bug was flagged by Meta Product Security.

This could be deliberate, though. High-profile attacks tend to draw a crowd, as well as increased interest from other threat actors looking to exploit zero-day flaws. Apple is known for hiding details of vulnerabilities until it is confident that a significant majority of affected devices have been patched.

“Extremely sophisticated attacks against specific targeted individuals” is also wording Apple usually uses for state-sponsored espionage attacks against diplomats and politicians, high-value targets such as tech CEOs, journalists, political opponents and dissidents, and similar. Although it is not mentioned in the report, tech companies like Apple and Google tend to notify the victims when they’re being targeted in such attacks.

The last time Apple used similar wording was in February 2026, when it patched CVE-2026-20700. In that incident it also did not discuss the attackers, or the victims, but we do know that it was discovered by Google’s Threat Analysis Group (TAG), a department assigned with investigating primarily state-sponsored hacking campaigns.

CVE-2026-86950 is now the second zero-day vulnerability the company patched this year. Last year, Apple addressed seven zero-day vulnerabilities exploited in the wild: CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43529, and CVE-2025-14174.

Given the severity of the flaw and what it can be used for, users are advised to apply the patches without delay. Apple users with automatic updates enabled should receive the security fix automatically, but those who haven't yet updated should manually check Settings → General → Software Update and install iOS/iPadOS 26.7.1.

Via BleepingComputer



Read the whole story
NerdsToGo
1 day ago
reply
Share this story
Delete
Next Page of Stories