SonicWall SMA1000 Zero-Days Hit Remote Access Infrastructure
SonicWall confirmed active exploitation of two SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410. The chain combines unauthenticated SSRF with code execution paths that can ultimately give attackers root-level control over exposed remote access appliances, making it one of the week’s most urgent edge-device stories.
Source: Help Net Security
Azure Permission Takeover Shows How One Credential Can Become Tenant-Wide Control
Sysdig documented an attack where a single leaked service principal credential turned into full Azure tenant compromise by the next morning. The attacker moved across multiple disconnected permission systems, established persistence on many identities, and seized visibility tooling meant to detect exactly this kind of intrusion.
Source: Sysdig
Hugging Face Discloses AI-Agent-Driven Internal Breach
Hugging Face said an autonomous AI agent system drove an intrusion from malicious dataset execution into internal clusters. The incident is notable not only because of the target, but because it is one of the clearest public examples so far of an end-to-end AI-assisted intrusion moving beyond proof-of-concept discussion.
Source: Hugging Face
AsyncAPI npm Compromise Pushes Multi-Stage Miasma Malware
Multiple official AsyncAPI npm packages were compromised and used to deliver a staged botnet loader tied to the Miasma family. The campaign shows that attackers are still finding ways around review controls by abusing repositories, publishing pipelines, and trusted package namespaces rather than relying on crude install-hook tricks alone.
Source: The Hacker News
Claude for Chrome Flaw Exposes Google Workspace Data
Researchers reported that Anthropic’s Claude for Chrome extension still contains unpatched issues that could let any extension with a content script on claude.ai trigger prompts against Gmail, Docs, and Calendar. In environments where users previously enabled more permissive execution settings, the impact rises from coerced approval to potentially silent enterprise data access.
Source: Manifold
ShinyHunters Tradecraft Shows How OAuth Abuse Becomes SaaS-Scale Access
Microsoft detailed how threat activity associated with ShinyHunters abused OAuth relationships, vishing, and trusted integrations to access SaaS applications such as Salesforce. The key lesson is that compromise can now spread through consent flows and business integrations that look legitimate enough to avoid many conventional login detections.
Source: Microsoft Security
Siemens ROX II Chain Delivers Persistent Root Access in OT Networks
Unit 42 and Siemens published a chained exploit involving three zero-days in Siemens ROX II switches. Together, the vulnerabilities allow privilege escalation and durable root-level access on devices that sit inside industrial control environments, which raises the operational importance well beyond a typical switch advisory.
Source: Unit 42
LegacyHive Adds Another Windows Zero-Day to the Nightmare Eclipse Stream
Nightmare Eclipse released LegacyHive, a local privilege escalation zero-day in the Windows User Profile Service. Even though the proof-of-concept was reportedly modified to make weaponization harder, the recurring public release of working Windows zero-days continues to create real defensive pressure around patch timing and local post-exploitation risk.
Source: SecurityWeek
Fake Coding Tests Hide OtterCookie-Aligned Malware in SVG Images
North Korea-linked operators behind the Contagious Interview cluster were observed using fake job and coding test lures that hid payload stages in SVG flag images. Victims who ran the project faced a multi-stage compromise that included credential theft, crypto wallet theft, remote access, and clipboard hijacking.
Source: The Hacker News
Ghostcommit Shows Prompt Injection Can Be Hidden Inside Images
Researchers demonstrated a pull request attack that hides prompt injection instructions inside a PNG image so AI code reviewers approve the change while missing the malicious logic. The technique matters because it targets a growing blind spot in AI-assisted development, where agents may inspect or process content differently from human reviewers.
Source: BleepingComputer
Chinese Operators Reportedly Used Claude Code and DeepSeek in Live Intrusions
Hunt.io described an intrusion campaign where Claude Code and DeepSeek were used as active parts of the operator workflow rather than as side tools. According to the report, they helped refine bypass methods, rework exploit logic after failure, and generate phishing infrastructure used against government and financial targets in four countries.
Source: Hunt.io
ClickLock Stealer Adds Another Modular macOS Threat to Watch
Group-IB uncovered a previously undocumented modular macOS stealer likely distributed through ClickFix-style pages, compromised WordPress sites, and Telegram infrastructure. The malware reportedly operates without elevated privileges or exploits, which makes the social engineering layer more important than any OS bypass.
Source: Group-IB
ACR Stealer Activity Rises Across Enterprise Environments
Microsoft observed increased ACR Stealer activity using ClickFix lures to steal browser credentials, tokens, and sensitive documents from enterprise systems. The campaigns reinforce how lightweight infostealers continue to be effective entry points for wider account compromise and follow-on cloud abuse.
Source: Microsoft Security
Accenture Confirms Breach After Source Code Theft Claims
Accenture confirmed a breach after a threat actor claimed to have stolen 35 GB of internal data, including source code, keys, and configuration material. Even without full public technical details, the incident stands out because of the type of data allegedly exposed and the risk it creates for downstream misuse.
Source: SecurityWeek
Fairlife Ransomware Incident Disrupts US Dairy Production
Coca-Cola disclosed that a ransomware attack affecting Fairlife disrupted production-related systems and temporarily halted dairy product manufacturing across the United States. It is a strong reminder that cyber incidents continue to move from IT inconvenience into direct operational and supply-chain impact in the physical economy.
Source: BleepingComputer
AresISEC d.o.o. · Zagreb, Croatia · OIB: 49411602130 · info@aresisec.hr
Privacy Policy | Terms of Service | Responsible Disclosure
© 2026 AresISEC