RSS Amplifier

Cyber Bites by Edwin Kwan · Jul 10, 2026

Cyber Bites - 10th July 2026

0
Sign in to vote or save

Edwin Kwan · Cyber Bites by Edwin Kwan

  • ACSC Issues Second Warning in Two Months Over Unpatched CMS Vulnerabilities Being Actively Exploited

  • OpenMandriva Linux Hit by Internal Sabotage Attempt from Former Contributor

  • China Warns Developers to Uninstall Claude Code Over ‘Backdoor’ Data Collection Fears

  • Phishing Campaign Impersonates Major Global Brands to Steal Gmail Credentials

https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms

The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued its second alert regarding content management system (CMS) vulnerabilities in as many months, warning that a large-scale attack campaign is actively exploiting known security flaws across websites globally. The alert identifies 17 specific vulnerabilities affecting a range of widely used platforms, including several WordPress plugins, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla’s JCE editor. Many of the affected organisations are small- to medium-sized businesses operating in Australia. The latest advisory follows a May warning from the ACSC about a ClickFix campaign in which compromised WordPress sites belonging to legitimate Australian businesses were used to deliver the Vidar Stealer malware to unsuspecting visitors.

Critically, patches are available for all 17 vulnerabilities listed in the alert, with some fixes having been released many months prior. Among the more notable flaws is CVE-2025-32432, a zero-day vulnerability in Craft CMS that was actively exploited for approximately two months before a patch was made available in April 2025.

The ACSC is urging administrators to actively check their systems for indicators of compromise, including webshells and malicious scripts that could allow attackers to maintain remote access. Where patches cannot be applied immediately, the agency recommends disabling vulnerable components as a stopgap measure. Organisations using managed hosting providers are encouraged to ask their providers directly how they are monitoring for and responding to active exploitation campaigns, reinforcing that shared responsibility for cybersecurity extends across the entire hosting supply chain.

https://forum.openmandriva.org/t/statement-regarding-attempted-distribution-sabotage/8997

The OpenMandriva Linux project has announced it was the target of an attempted act of internal sabotage carried out by a former contributor following a dispute within the community. According to long-time developer and maintainer, the incident was triggered by a contributor’s abusive behaviour towards other users and members of the distribution, which ultimately caused several contributors to leave the project. In response, the accused leveraged his administrative privileges to delete portions of a repository the team had spent nearly a decade building. The person had originally been granted those privileges after assisting with migrating and mirroring project repositories to his private OneDev instance.

The destructive actions went beyond simply wiping GitHub repositories. The person also pushed an empty package into OpenMandriva’s Cooker development repository that effectively obsoleted packages for both the GNOME and Cosmic desktop environments, potentially putting users’ systems at risk. The OpenMandriva team is currently working to restore the deleted repositories and packages, while also conducting a full system audit to identify any further unauthorised changes. The person has since disputed the characterisation of his actions, claiming that his intent was not to harm the distribution or its users, and that the deletions were a deliberate but targeted response to what he described as other members removing build specification files from repositories without consultation.

Despite acknowledging that the actions likely constitute a criminal offence, the OpenMandriva team has confirmed it will not be pursuing legal action against the former contributor. The incident serves as a reminder of the security risks that can arise from insider access within open-source community projects, particularly when contributor relationships break down.

https://cnvdb.org.cn/announcement/2074682031259299842

China’s National Vulnerability Database (CNVDB) has urged developers to immediately uninstall recent versions of Anthropic’s Claude Code, citing concerns over what it describes as “backdoor code” capable of collecting sensitive user data without consent. The state-run body claimed via WeChat and an official online statement that a built-in monitoring mechanism within Claude Code versions 2.1.91 through 2.1.196, released between 2 April and 29 June, could gather details such as a user’s location and identity and forward them to remote servers. The CNVDB has recommended that affected organisations conduct a comprehensive investigation and either uninstall the software or upgrade to the latest version, while also strengthening access controls and traffic monitoring on development tools within core business networks.

The concerns appear to stem from a covert anti-distillation mechanism that Anthropic quietly introduced in March, designed to prevent competing AI companies from training their own models on Claude’s responses — a practice known as model distillation. Claude Code engineer Thariq Shihipar publicly acknowledged the experiment, noting that stronger mitigations had since been implemented and that the steganography system was removed in version 2.1.198, released on 1 July. Anthropic has not responded to questions about whether the mechanism was disclosed in its terms of service, and the company did not immediately respond to requests for comment regarding China’s alert.

The row over alleged user tracking is just one element of a broader deterioration in relations between Anthropic and China. The AI company was previously embroiled in a public dispute with Chinese tech giant Alibaba, which it accused of using Claude’s outputs to train its own models — described by Anthropic in a letter to two US senators as the largest attack on its AI the company had ever experienced. More recently, Alibaba has reportedly banned its own staff from using Claude altogether, citing fears the tool could be used to identify Chinese users, according to the South China Morning Post.

https://gist.github.com/BushidoUK/57c38d5ee75481fb237e968a537de778

A highly targeted phishing campaign has been uncovered in which attackers are posing as recruiters from some of the world’s most recognisable brands to harvest victims’ Gmail credentials. The operation is notable for its level of personalisation, targets are addressed by name and appear to be selected based on their professional field, suggesting the attackers conducted prior reconnaissance before making contact. Victims receive emails purportedly offering marketing role interviews, and are directed to click a link to book a meeting, at which point they are prompted to hand over their Gmail login details via a convincing Browser-in-the-Browser pop-up that mimics a legitimate Google sign-in page.

What makes this campaign particularly sophisticated is its use of nested redirects across multiple legitimate platforms to evade detection. The initial phishing email is sent through PeopleForce, a genuine cloud-based HR and applicant tracking platform, lending the communication an air of authenticity. From there, the link chains through Salesforce Marketing Cloud’s ExactTarget service, then to Wise Agent, before ultimately landing the victim on a Netlify-hosted phishing site. The breadth of impersonated organisations is alarming, spanning industries including airlines such as American Airlines, Delta, and United; food and beverage giants Coca-Cola, PepsiCo, and Red Bull; luxury brands Louis Vuitton and Adidas; and tech and consulting firms including OpenAI, McKinsey & Company, and Adobe, among many others.

Security researchers have published a list of indicators of compromise associated with the campaign, comprising dozens of fraudulent domains designed to closely mimic legitimate career and hiring portals for the targeted organisations. Individuals working in marketing or related fields are urged to exercise extreme caution when receiving unsolicited recruitment emails, particularly those requesting Google account credentials at any stage of the process. Organisations whose brands are being impersonated should consider alerting their candidate communities and monitoring for fraudulent domains operating under their names.

Read the original on edwinkwan.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.