The Signal
Must Know
Incident · Malwarebytes Labs
What happened
Researchers at Manifold Security found third-party[.]com, an ordinary domain often used in documentation for an external website, API, or service, serving a fake Cloudflare-style verification page to Windows visitors. [1]
The page urged visitors to open the Windows Run box and paste a clipboard-copied command designed to download and execute a PowerShell script; the script-hosting domain was not resolving at the time of writing. [1]
Why it matters
ClickFix is described as social engineering that convinces victims to run commands themselves, often using legitimate operating-system tools and the permissions of the persuaded user; consequences can range from information theft to more serious company-network compromise. [1]
AI & Agents · Krebs On Security
What happened
Cameron John Wagenius, a U.S. Army soldier stationed in South Korea, pleaded guilty to hacking telecommunications companies and stealing mobile call and text metadata from more than 100 million AT&T customers; he was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution. [2]
The intrusions involved Snowflake customers with exposed credentials and no enforced multi-factor authentication; Snowflake has since mandated MFA on all accounts. [2]
Why it matters
Federal investigators characterized the case as a serious insider-threat investigation because Wagenius was an active-duty soldier with secret clearance allegedly creating hacking tools and trafficking in data. [2]
AI & Agents · Malwarebytes Labs
What happened
LinkedIn is adding verification features intended to make fabricated professional identities, work histories, and company impersonation harder, in response to generative AI lowering the cost of creating convincing profiles and outreach. [3]
The features include colleague or classmate confirmations of work or study affiliations; these confirm an affiliation but do not assess ability or recommend the person. [3]
Why it matters
The checks may help establish whether a recruiter is affiliated with a recognized company, but may be less useful when scammers invent the employer itself or operate a fraudulent company Page. [3]
Vulnerability · Cyberscoop
What happened
The Supreme Court ruled that states may use the federal SAVE database to verify voter citizenship, reversing lower-court decisions that found the database inaccurate and likely to disenfranchise eligible voters. [4]
DHS originally designed SAVE for immigrant benefit eligibility and citizenship-applicant tracking; the Trump administration repurposed it to screen voters for citizenship. [4]
Why it matters
Critics characterize SAVE as outdated and often inaccurate, with a significant risk of wrongly removing eligible voters from rolls; DHS admits its data is not perfect and evidence suggests significant flaws. [4]
Also Worth Knowing
Incident · Securityaffairs
What happened
Bitget says suspected North Korea-linked actors stole $351.6 million from a limited number of hot and warm wallets. [5]
Exploitation · The Hacker News
What happened
CISA added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. [6]
Policy · Malwarebytes Labs
What happened
ShipmentsFree is described as a rebate service rather than a shipping company; its FAQ says members can claim up to $100 per month in shipping and return rebates if they submit proof of eligible costs. [7]