Jira, Confluence Among Eight Atlassian Products Under Attack
Attackers are targeting an Atlassian vulnerability affecting eight products, including Jira, Confluence, and Bitbucket.
The flaw allows unauthenticated access to files in self-hosted deployments when attackers know the exact file path.
Attackers began probing the flaw within hours of the PoC becoming public, showing just how quickly the exploitation window can open.
Patch affected Atlassian instances, review access logs for suspicious file requests, and rotate potentially exposed credentials.
Malicious npm Packages Hit 40,000 Downloads
Researchers uncovered eight malicious npm packages tied to MALFEX with over 40,000 downloads.
The packages delivered remote access malware and information stealers targeting Windows systems.
The fact that one malicious package remained available for over a year shows how long these threats can go unnoticed.
Check dependencies for malicious packages, monitor suspicious installation activity, and investigate affected developer systems before rebuilding.
Fiddler Classic Flaws Put Windows Systems at Risk
Progress patched four Windows Fiddler Classic flaws, including one that could allow attackers to execute code with administrator privileges.
Exploitation requires local access or specific conditions, and no active attacks have been reported.
What concerns me is the certificate flaw, which could allow attackers to install a malicious root certificate trusted across Windows. This could enable them to intercept encrypted traffic without users knowing.
Update Fiddler Classic to the latest patched version and restrict machine-wide certificate installation to authorized administrators.
Fake AI Ads Platforms Steal Passwords, MFA Codes
Researchers uncovered fake AI advertising tools impersonating ChatGPT, Gemini, and Claude to steal credentials.
The attackers spoof Google and Okta logins to steal passwords and manipulate MFA challenges in real time.
What stands out to me is that attackers can add unauthorized administrators to compromised advertising accounts. This allows them to maintain access even after the original credentials are reset.
Enforce phishing-resistant MFA and audit advertising accounts for unauthorized administrators, connected apps, and permission changes.
Are Your Build Pipelines Secure?
Malicious software dependencies can steal credentials and spread malware while evading traditional vulnerability scanners.
How to reduce software supply risk:
- Audit software dependencies by maintaining an SBOM and reviewing third-party packages for vulnerabilities or malicious code.
- Use DevSecOps tools to automate security scanning in CI/CD pipelines and detect threats before deployment.
- Secure build environments by restricting permissions, verifying package integrity, and monitoring suspicious installation activity.
Greater visibility into software dependencies helps organizations identify supply chain risks earlier in the development process.
FBI: FortiBleed Can Lock Out Firewall Admins
The ongoing FortiBleed campaign against Fortinet firewalls remains a critical threat. The FBI and Secret Service warn that threat actors are still milking a stash of 86,000-plus compromised credentials to hijack devices. Once inside, these digital squatters set up rogue admin accounts, boot legitimate IT teams, and roll out the red carpet for ransomware affiliates.
Since a shiny new firmware update won’t evict an attacker already holding the keys, security teams must actively hunt for lingering access.
Scrutinize accounts, API keys, and logs for unauthorized changes. Sever active VPN sessions, enforce phishing-resistant MFA, and use Fortinet’s PBKDF2 guidance to scrub legacy password hashes. If you spot a ghost in the machine, isolate the affected systems immediately.
Your firewall shouldn’t give an intruder administrator privileges and hand you a password-reset headache.
Fake ChatGPT and Gemini Tools Steal Ad Accounts
Scammers know marketers can’t resist shiny new AI toys. So threat actors are now dangling fake ChatGPT and Gemini marketing tools to hijack manager accounts, according to Island researchers. Clicking “Connect” spawns a counterfeit login prompt that is essentially a fake browser trapped inside your real one.
Behind the curtain, a live human plays puppet master. They intercept your passwords, demand MFA codes, and log in alongside you. One stolen login hands criminals the master keys to drain multiple clients’ ad budgets.
Spot the trap by dragging the pop-up; a fake window is caged inside the main browser tab. Stick to phishing-resistant passkeys. If you already took the bait, have admins nuke your access and audit your campaigns immediately.
Because “optimizing your ad spend” shouldn’t mean funding a cybercriminal’s startup.