Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026

    Being a Luddite Is Fun Again

    July 27, 2026

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Infosec News Nuggets — July 27, 2026 – AboutDFIR
    News

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    adminBy adminJuly 27, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

    Researchers published a working exploit on July 24 for a flaw dubbed Certighost that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine, then use the resulting Kerberos credential to pull the krbtgt secret through DCSync and take over an entire domain. Tracked as CVE-2026-54121 with a CVSS score of 8.8, the bug lives in an AD CS enrollment fallback that let a certification authority trust a requester-supplied directory server without first confirming it was a real Domain Controller. Microsoft patched the issue on July 14, and organizations running an Enterprise CA are urged to apply that update on AD CS hosts, since exploitation needs only network access and a standard domain account.

     

    OnTrac notifies customers of data breach after network hack

    Parcel delivery company OnTrac is notifying customers that hackers breached its corporate network and accessed files between March 20 and 22, though the exact data elements exposed were redacted in the notification sample shared with regulators. The company brought in a third-party specialist to scope the intrusion and says it took steps to ensure the accessed data was “re-secured and not distributed,” language that suggests some form of agreement was reached with the attackers. Affected individuals are being offered a year of free credit monitoring and identity protection, and as of the notification no ransomware or extortion group had publicly claimed responsibility for the attack.

     

    CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy

    CISA and the FBI updated a joint advisory warning that Iran-affiliated hackers are broadening their campaign against internet-exposed programmable logic controllers used in water, energy, and other municipal infrastructure, expanding beyond earlier Rockwell Automation targets to include Schneider Electric and Siemens devices. The agencies said the threat groups have already disrupted sites by exploiting default credentials, insecure remote access, and unpatched firmware, in one case using Dropbear SSH to gain remote access to a targeted system. Organizations were urged to change default passwords, enforce multifactor authentication, patch promptly, and place these devices behind a VPN, proxy, or firewall rather than exposing them directly to the internet.

     

    Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife

    The Anubis ransomware group has claimed credit for the attack that forced Coca-Cola subsidiary Fairlife to suspend U.S. dairy production, listing the companies on its leak site and claiming to have encrypted servers and exfiltrated a terabyte of confidential data. The group gave Coca-Cola roughly a week to pay before the stolen data is published, and offered to help restore systems quickly if a ransom is paid. Active since late 2024, Anubis has previously drawn scrutiny for a wiper feature that can permanently destroy victim files even after a double-extortion attack, raising the stakes for organizations weighing whether to negotiate.

     

    Ubuntu snap-confine Vulnerability Enables Local Root Access

    Qualys researchers disclosed a high-severity race condition in Ubuntu’s snap-confine component, tracked as CVE-2026-8933, that lets any local user gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The flaw traces back to a 2025 hardening change that moved snap-confine from a set-user-ID-root binary to a set-capabilities model, leaving a narrow window during sandbox setup where an attacker can mount a FUSE filesystem and plant symlinks to redirect root-owned writes, then drop a malicious udev rule to force systemd-udevd to execute commands as root. Canonical has released patches, and administrators are urged to update snapd immediately since the affected package ships by default across employee workstations and servers alike.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMeta Logging Every Employee Keystroke | Threat Wire
    Next Article Being a Luddite Is Fun Again
    admin
    • Website

    Related Posts

    News

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026
    News

    Being a Luddite Is Fun Again

    July 27, 2026
    News

    GitHub, PyPI add time-absed defenses against supply chain attacks

    July 26, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026

    Being a Luddite Is Fun Again

    July 27, 2026

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.