Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.
Redis 6.2.23, 7.2.15, and 7.4.10
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.
The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.
New Dolphin X malware uses AI to rank high-value targets
Australian energy provider Origin says data breach exposes client data
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.
The NSA, CISA and partner agencies published
