Posts

The Hidden Flaw: Why Caller ID Spoofing Is So Easy

Image
  It’s easy for phishers to hijack caller ID for smishing because the global telephone system was never designed to authenticate who is actually sending a call or text . Modern attackers exploit these structural weaknesses with cheap VoIP tools, SMS gateways, and cybercrime‑as‑a‑service platforms. The short version: caller ID is “asserted,” not verified — and attackers can simply lie. The core reasons spoofing is so easy 1. Legacy telecom protocols trust whatever caller ID is provided Traditional phone networks run on SS7 , a signaling system built decades ago when only national carriers interconnected. SS7 assumes all participants are trustworthy , so it accepts whatever caller ID a network claims without cryptographic verification. This “trust by default” model is fundamentally incompatible with modern threat actors. 2. VoIP and SIP make spoofing trivial VoIP systems use SIP headers (e.g., From , Contact , P‑Asserted‑Identity ) that can be manipulated by the sender. Attackers ca...

The Backdoor You Can’t Delete: WordPress Malware That Regenerates After Removal

Image
  SC WordPress backdoor is specifically engineered to rebuild itself after cleanup , using a self‑healing mesh of persistence layers across files, the database, and shared memory . Removing visible malware does nothing if even one persistence node survives.  The SC backdoor is not a single file — it’s a redundant network of loaders, drop-ins, fake plugins, database payloads, and shared-memory segments . Each component can recreate the others , forming a circular recovery loop. Core behaviors Lives in at least eight locations at once (files, DB, shared memory). Any surviving component rewrites missing ones on the next page load. Uses early‑loading WordPress hooks (auto_prepend, drop-ins, mu‑plugins). Stores full payloads in the database and in System V shared memory , allowing reinfection even after disk cleanup. Hides itself from plugin lists and update checks , and can forge admin cookies. Deleting the malicious plugin or file does not remove the backdoor. Here’s how th...

RAT Delivery Goes High‑Fidelity: The Security Risks Behind AI‑Generated Phishing Content

Image
  How Attackers Turn ChatGPT‑Style Content Into RAT Delivery Lures — And Why Defenders Should Care Remote Access Trojans (RATs) remain one of the most persistent threats facing organizations today. While the malware itself hasn’t changed dramatically, the delivery mechanisms have — and generative AI has become part of that evolution. Attackers aren’t using AI to generate malware; they’re using it to polish the social‑engineering layer that gets victims to install it. What’s Actually Happening Cybercriminals are increasingly leveraging AI writing tools to create high‑quality phishing lures , making malicious emails look more legitimate, more personalized, and more convincing than ever. These lures are then paired with RAT payloads delivered through: Malicious attachments (fake invoices, resumes, shipping notices) Weaponized documents exploiting known vulnerabilities Links to compromised websites hosting installers Fake “security updates” or “account verification” prompts The AI‑ge...

Critical FortiMail Flaw Enables Pre‑Auth File Write, Opening the Door to Full Compromise

Image
  Unauthenticated attackers can write arbitrary files on FortiMail appliances via crafted HTTP/HTTPS requests. On a Linux‑based perimeter email gateway, arbitrary file write = practical remote code execution (RCE) . This flaw is confirmed exploited in the wild and added to CISA’s KEV catalog. CVE‑2026‑104286 combines two weaknesses: Path Traversal (CWE‑22) — FortiMail fails to sanitize directory traversal sequences ( ../ , encoded variants). Improper NULL Byte Neutralization (CWE‑158) — %00 truncates paths at the OS level, bypassing validation. Together, these allow attackers to write files anywhere on the filesystem through the web‑facing management or service interface.  Once an attacker can write arbitrary files, they can: Drop a webshell into a served directory Modify cron jobs Overwrite binaries invoked by privileged services Add SSH authorized_keys Plant persistence in FortiMail’s internal daemons Security researchers emphasize that this should be treated as an act...

SalesBleed: Salesforce Agentforce Flaws Expose CRM Data Without a Click

Image
  “SalesBleed” Exploits Salesforce AI Agents for Zero-Click Data Theft A newly disclosed set of vulnerabilities dubbed “SalesBleed” affected Salesforce Agentforce, demonstrating how an attacker could manipulate trusted AI agents to exfiltrate CRM data without a victim clicking a malicious link and potentially use those agents to conduct phishing through internal Slack channels. Researchers at Zenity Labs disclosed the findings on September 24, 2026. How SalesBleed Worked SalesBleed consists of three vulnerabilities involving Agentforce. Two could enable zero-click data exfiltration, while the third could allow an attacker to abuse an Agentforce-Slack integration to distribute phishing messages. The attack began with a surprisingly ordinary entry point: a public Salesforce Web-to-Lead form . An attacker could: Submit a poisoned sales lead containing malicious AI instructions through a public Web-to-Lead form. No Salesforce authentication was required. The malicious instructions ...

ShinyHunters Claims Unprecedented FBI Hack, 2–3 TB of Data Allegedly Exfiltrated

Image
ShinyHunters claimed that it breached the Federal Bureau of Investigation (FBI) and exfiltrated roughly 2 to 3 TB of data. The claim is significant, but there is an important qualification: as of the latest reporting, the FBI has not publicly confirmed the claimed compromise or the scope of the alleged data theft. According to reporting published by The Register on September 22: Initial compromise: ShinyHunters says it exploited a previously unknown vulnerability in Oracle PeopleSoft exposed through the FBI's jobs website. The vulnerability allegedly provided remote code execution (RCE) on the affected servers. Website defacement: After obtaining access, the attackers reportedly defaced the FBI recruitment site with a message claiming the site had been seized by ShinyHunters. At the time of The Register's reporting, the FBI jobs site subsequently displayed a maintenance message. Lateral movement: The group claims it was able to move beyond the compromised recruitment in...