Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-2 of 2 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 01 Oct 2026, 12:32 AM | The Hacker News | 4.5 | Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft Security Research reported a phishing campaign, detected in July 2026, that delivers a digitally signed MSP360 RMM v2.5.0.67 installer disguised as meeting invites, PDF readers, software updates, and e-card/RSVP lures (e.g. VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, SSA.GOV_STATEMENT_rmm_v2.5.0.67_oid[redacted].exe). The installer relaunches itself through the Windows UAC elevation flow, drops DLLs, registers RMM.Agent.exe and RMM.Agent.Launcher.exe as Windows services with Registry autorun entries, and opens inbound UDP port 48678 in Windows Firewall. It then uses MSP360 to run PowerShell that installs a ConnectWise ScreenConnect client as a second, redundant remote-access channel for tool delivery and credential access. Payloads were staged on both attacker infrastructure and legitimate services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Microsoft did not attribute the activity to any known threat actor. Why: The thing that got past defences was a valid vendor signature on a legitimate MSP360 binary, so 'it's signed' is not a trust decision on its own — the detectable signal here is the lure filename pattern (_rmm_v2.5.0.67_oid...) and the combination of an RMM service plus a ScreenConnect install on the same host. If you don't deploy MSP360 RMM anywhere, you can alert or block on RMM.Agent.exe / RMM.Agent.Launcher.exe services, autorun registry entries, and outbound UDP 48678 rather than waiting for an AV signature. If you run any file-hosting or storage product (S3, R2, Dropbox, GitLab, Supabase were all used as staging), treat abuse-reporting and takedown for hosted installers as an operational cost, not an edge case. There is no Malaysia-specific angle in this report, so treat it as a generic endpoint-detection change. |
| 29 Sep 2026, 3:18 AM | The Hacker News | 3.0 | Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple shipped iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that allows arbitrary code execution when processing a maliciously crafted file, patched with improved bounds checking. Apple says it is aware of a report that the bug may have been exploited in an 'extremely sophisticated attack against specific targeted individuals' on iOS versions before iOS 27, and credits Meta Product Security for reporting it. Apple disclosed no numbers on how many people were targeted, whether any attempts succeeded, or when exploitation first occurred; the affected device list runs from iPhone 11 and later through iPad 8th generation and later, plus Macs on Tahoe and Sequoia. The write-up also notes Apple's February fix for a dyld memory corruption issue (CVE-2026-20700, CVSS 7.8) that it said had been weaponized. Why: This is a targeted-attack CVE, not a mass-exploitation one, so the practical action is narrow and cheap: if you are on a Mac running macOS Tahoe or Sequoia, or an iPhone 11 / iPad 8th gen or later, update to 26.7.1 or 15.8.1 now, and make sure any Mac CI runner, build box, or design workstation that opens untrusted files (images, PDFs, documents) is on the patched build rather than pinned to an older macOS for tooling reasons. The interesting detail for teams is the source: Meta Product Security found it, meaning file-parsing bugs in Apple's graphics stack are being found by offensive-grade research, so treat untrusted-file handling on Apple platforms as an attack surface you version-control, not just a user problem. |