Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Multiple Vulnerabilities in QNAP NAS Devices Resolved Through Security Updates Ashish Khaitan
    A series of vulnerabilities in QNAP NAS products has prompted security warnings after researchers identified flaws that could allow attackers to execute arbitrary commands, bypass security controls, disclose sensitive information, or disrupt system operations. The issues affect several QNAP platforms, including QTS, QuTS hero, QuTS cloud, and QVP appliances. The security advisory, identified as QSA-26-10, was released by QNAP on June 17, 2026, while a related security notice was published on
     

Multiple Vulnerabilities in QNAP NAS Devices Resolved Through Security Updates

vulnerabilities in QNAP NAS

A series of vulnerabilities in QNAP NAS products has prompted security warnings after researchers identified flaws that could allow attackers to execute arbitrary commands, bypass security controls, disclose sensitive information, or disrupt system operations. The issues affect several QNAP platforms, including QTS, QuTS hero, QuTS cloud, and QVP appliances. The security advisory, identified as QSA-26-10, was released by QNAP on June 17, 2026, while a related security notice was published on June 24, 2026. The vulnerabilities were assigned an “Important” severity rating and have since been marked as resolved through updated software releases.

Affected Products from Vulnerabilities in QNAP NAS

The reported QNAP NAS vulnerabilities impact QTS 5.2.7, QuTS hero h5.2.8, QuTS cloud c5.2.8, and QVP 2.7.1. According to the advisory, successful exploitation could lead to denial-of-service conditions, information disclosure, elevation of privileges, remote code execution, and security restriction bypass. One of the most notable flaws, CVE-2025-59382, is a URL injection vulnerability. QNAP explained that “a remote attacker can modify the password reset URL and trick a victim into visiting an attacker-controlled password reset page, leading to credential theft.”

Command Injection and Buffer Overflow Risks 

Several command injection vulnerabilities were also disclosed. CVE-2025-66273 allows an authenticated administrator to inject arbitrary system commands through a username parameter. Similar command execution issues were identified in CVE-2025-66279, involving user deletion APIs, and CVE-2026-22893, which could enable command execution with elevated privileges. Additional vulnerabilities in QNAP NAS devices involve memory handling weaknesses. CVE-2025-62858 is a stack overflow vulnerability that may cause memory corruption and unexpected behavior when exploited by an administrator. CVE-2025-66280 and CVE-2025-68405 can result in unexpected system behavior or denial-of-service conditions. QNAP also disclosed three stack-based buffer overflow vulnerabilities: CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241. These flaws can enable unauthorized actions or cause CGI service crashes through excessively long filenames during file upload operations.

Access Control and Resource Consumption Issues 

Among the other QNAP NAS vulnerabilities, CVE-2026-24724 involves broken access control that may allow authenticated users to bypass restrictions and access sensitive files. Meanwhile, CVE-2026-22899 can trigger a NULL pointer dereference in utilRequest.cgi, resulting in a denial-of-service condition.  Another issue, CVE-2026-24720, is an uncontrolled resource consumption vulnerability that could cause excessive CPU and memory usage, reducing overall system responsiveness. QNAP also warned that CVE-2025-66281, a pre-authentication NULL pointer vulnerability, can be triggered through a malformed HTTP request with a missing or empty content-length header. 

Fixed Versions and Recommendations 

QNAP has released patches for all affected products. The fixes are available in QVP 2.8.0, QuTS cloud C5.2.9, QTS 5.2.9.3499, and QuTS hero h5.2.9.  To mitigate risks associated with CVE-2025-59382 and other vulnerabilities in QNAP NAS systems, administrators are advised to update their devices to the latest firmware versions. QNAP recommends regularly checking for software updates and applying vendor-issued security patches to reduce exposure to newly discovered threats. 

Google Sues Operators of AI-Powered ‘Outsider’ Phishing Kit Linked to 1.5 Million URLs

Outsider AI phishing kit

Google has launched a lawsuit against the operators behind the Outsider AI phishing kit. This alleged AI phishing kit, the company says, has been used to create convincing phishing websites using artificial intelligence tools, including Google's Gemini.   The legal action, filed by Alphabet-owned Google in a federal court in Manhattan, targets the developers of the Outsider phishing platform. According to the complaint, the software enables users to replicate hundreds of trusted websites and provides detailed guidance on generating phishing pages designed to steal personal and financial information.   Google alleges that the AI phishing kit leverages AI capabilities, including Gemini, to make fraudulent websites more sophisticated and harder to identify. 

Google Alleges the Outsider AI Phishing Kit Enabled AI-Powered Cybercrime 

In its lawsuit, Google claims that the operation of the Outsider AI phishing kit has facilitated large-scale cybercrime by giving bad actors access to tools that simplify the creation of phishing campaigns. The company alleges that the AI phishing kit can imitate legitimate websites while offering step-by-step instructions that help users generate convincing phishing pages through AI-assisted processes.  The lawsuit places particular emphasis on alleged Gemini misuse, arguing that Google's AI tools were exploited to support phishing activities. According to Google, the developers behind Outsider used AI technologies in ways that violate the company's policies and contribute to online fraud.  Google also alleges that the individuals responsible for the Outsider AI phishing kit are anonymous cybercriminals based in China. The company claims these actors abused services such as Google Cloud and Google Drive while also misusing Google's trademarks to create a false sense of legitimacy around their operations. 

More Than 1.5 Million URLs Linked to the AI Phishing Kit 

The scale of the alleged operation is one of the most significant aspects of the lawsuit. Google reported that it identified more than 1.5 million URLs associated with the Outsider AI phishing kit between November and April.  The large number of detected URLs suggests that the phishing infrastructure was extensive and capable of reaching a substantial number of potential victims. Google's findings highlight how rapidly phishing operations can expand when aided by automation and AI-driven tools.  As concerns about Gemini misuse and AI-enabled cybercrime continue to grow, security experts have warned that phishing attacks are becoming increasingly difficult for users to distinguish from legitimate communications. 

Google Partners With FBI and Telecom Providers 

Google says it is taking a coordinated approach to disrupt the Outsider network. In a blog post, Google General Counsel Halimah DeLaine Prado stated that the company is working alongside the Federal Bureau of Investigation (FBI) as well as major telecommunications companies including AT&T, T-Mobile, and Verizon.  According to DeLaine Prado, the collaboration aims to dismantle the infrastructure supporting the Outsider AI phishing kit. The effort combines legal action, industry cooperation, and technical measures to address what Google views as an evolving cybersecurity threat.  The partnership reflects a broader trend within the technology and telecommunications sectors, where organizations are joining forces to combat sophisticated phishing operations and online fraud schemes. 

Rising Concerns Over Gemini Misuse and AI-Driven Scams 

The lawsuit also draws attention to wider concerns across the cybersecurity industry about the misuse of artificial intelligence. Experts have warned that AI tools can help criminals create more persuasive messages, realistic websites, and effective social engineering campaigns.  Commenting on the issue, Brett Leatherman, Assistant Director of the FBI's Cyber Division, said that criminals are increasingly turning to AI to make fraudulent activity more convincing and more difficult to detect.  Leatherman emphasized the importance of public-private partnerships in disrupting cybercriminal operations, pointing to collaborations such as the one between Google and the FBI as a key component in combating modern digital threats.  The allegations surrounding Gemini misuse serve as another example of how AI technologies, while beneficial in many legitimate applications, can also be exploited by malicious actors seeking to improve the effectiveness of phishing attacks. 

Legislative Efforts to Combat AI-Powered Fraud 

Beyond its lawsuit against Outsider, Google is also advocating for policy measures aimed at reducing online scams. DeLaine Prado noted that the company supports seven bills currently pending in the U.S. Congress that are intended to address scamming activities.  Google's backing of the proposed legislation signals a broader effort to combine legal, technological, and policy-based responses to the rise of AI-enabled cybercrime. The company argues that tackling threats such as the Outsider AI phishing kit requires cooperation across government agencies, technology providers, law enforcement organizations, and lawmakers.  As AI tools continue to evolve, the lawsuit against Outsider highlights the growing challenge facing the cybersecurity sector. The case not only focuses on the alleged abuse of Google's services and trademarks but also raises larger questions about preventing Gemini misuse and limiting the role of AI in sophisticated phishing campaigns. 

Splunk Urges Immediate Patching of Critical Flaw Enabling Arbitrary File Operations

CVE-2026-20253

A newly disclosed security vulnerability in Splunk Enterprise has prompted urgent patching efforts after researchers revealed that the flaw could allow unauthenticated attackers to perform arbitrary file operations and potentially achieve remote code execution. The issue, identified as CVE-2026-20253, affects certain versions of Splunk Enterprise and carries a critical CVSS score of 9.8.  The vulnerability stems from weaknesses in a PostgreSQL sidecar service used within affected deployments. While Splunk Cloud remains unaffected, organizations running vulnerable on-premises versions of Splunk Enterprise are being urged to install security updates as soon as possible. 

CVE-2026-20253 Affects Multiple Splunk Enterprise Versions 

According to a security advisory issued by Splunk, the flaw exists in Splunk Enterprise versions below 10.2.4 and 10.0.7.  The company explained the issue in the following statement:  "In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint."  Splunk further noted:  "The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials."  Because the affected PostgreSQL endpoint does not enforce authentication requirements, attackers with network access can interact with it without providing valid credentials, creating a security risk for exposed systems. 

Patched Versions and Affected Releases 

Splunk has released updates to address CVE-2026-20253 across affected product lines.  The impacted and fixed versions are: 
  • Splunk Enterprise 10.0.0 through 10.0.6 — fixed in 10.0.7 
  • Splunk Enterprise 10.2.0 through 10.2.3 — fixed in 10.2.4 
  • Splunk Enterprise 10.4 — not affected 
The company also clarified that Splunk Cloud is not vulnerable to this issue because the platform does not utilize the PostgreSQL sidecars associated with the flaw. 

How Attackers Could Exploit the PostgreSQL Weakness 

Security researchers explained that threat actors could exploit CVE-2026-20253 by abusing PostgreSQL functionality to write attacker-controlled files onto a target system.  One key component of the attack involves lo_export, a PostgreSQL function capable of extracting a BLOB (Binary Large Object) from a database and saving it as a file on the underlying filesystem. By creating a malicious function that leverages lo_export, an attacker could write arbitrary content to files on the Splunk server.  The attack becomes more dangerous when the malicious function is executed during a database restoration process. This allows the attacker-controlled content to be written directly to the filesystem, opening a pathway to further compromise. 

From Arbitrary File Write to Remote Code Execution 

Researchers noted that obtaining arbitrary file-write capabilities within Splunk Enterprise can serve as a stepping stone toward full remote code execution.  An attacker could overwrite Python scripts that are routinely executed by Splunk services. One example highlighted is:  /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py  By replacing or modifying such scripts with malicious code, an attacker could cause the payload to execute automatically when the script runs, effectively granting remote code execution on the affected system. 

Attack Chain Associated With CVE-2026-20253 

The disclosed exploitation sequence involves several steps: 
  1. Create a database and configure it to allow user authentication without a password while granting permissions required to execute functions such as lo_export. 
  2. Use the /backup endpoint to place a dump of the remote database onto the Splunk filesystem. 
  3. Use the /restore endpoint to import the malicious database dump, triggering execution of the attacker-created function during restoration and writing a malicious Python script to the filesystem. 
Through this process, attackers can leverage the vulnerable PostgreSQL sidecar service to transform a file-write capability into a mechanism for executing arbitrary code. 

Salesforce Marketing Cloud Vulnerabilities Expose Cross-Tenant Subscriber Data Risks

Salesforce AMPScript

A recently disclosed set of vulnerabilities in Salesforce Marketing Cloud, widely known as SFMC, has drawn attention to the security risks tied to centralized marketing infrastructure.   The flaws, which affected components tied to AMPScript, CloudPages, and email-rendering workflows, could have enabled attackers to access subscriber information, enumerate marketing emails, and potentially affect organizations across multiple tenants.  Security researchers found that weaknesses in SFMC’s templating engine and cryptographic implementation introduced opportunities for unauthorized data access across customer environments. 

AMPScript and SFMC Template Injection Risks 

Modern enterprises rely heavily on Salesforce Marketing Cloud to manage large-scale marketing campaigns, personalized customer journeys, and trackable email communications. The platform, formerly known as ExactTarget, supports dynamic content generation through technologies such as AMPScript, Server-Side JavaScript (SSJS), and internal data views connected to large subscriber databases.  While these features provide flexibility for marketers, researchers noted that they also increase the impact of any underlying vulnerability. One of the major concerns centered on SFMC’s server-side templating framework.  AMPScript and SSJS allow organizations to dynamically insert subscriber attributes such as names, email addresses, and engagement metrics directly into marketing content. However, functions like TreatAsContent introduced a dangerous behavior because they effectively evaluate user-controlled input as executable template code. Researchers explained that if attacker-controlled data was passed into these functions, it could trigger template injection inside Salesforce Marketing Cloud environments.  The issue became more severe because SFMC historically supported AMPScript execution within email subject lines. According to the findings, legacy behavior caused subject templates to be evaluated twice by default. That design opened the door for payload execution during the second rendering stage. Researchers demonstrated the risk using the following payload inside a name field:  %%=RowCount(LookupRows("_Subscribers","SubscriberKey",_subscriberkey))=%%  If processed during the second evaluation phase, the payload could execute successfully and create a reliable injection point inside the marketing workflow.  Once template execution was achieved, attackers could potentially use built-in SFMC functions such as LookupRows to query internal Data Views, including: 
  • _Subscribers  
  • _Sent  
  • _Job  
  • _SMSMessageTracking  
  • _Click  
Access to these views could expose subscriber lists, email delivery records, engagement metrics, and message history associated with affected Salesforce Marketing Cloud tenants. 

CloudPages and “View Email in Browser” Vulnerability

Researchers identified an even more serious vulnerability tied to SFMC’s “view email in browser” functionality and CloudPages infrastructure. Many Salesforce customers configure branded domains such as view.example.com or pages.example.com that route back to shared SFMC infrastructure. These links typically rely on an encrypted qs parameter containing tenant and message-specific information. According to researchers from Searchlight Cyber, the older “classic” qs implementation used unauthenticated CBC encryption. The researchers found that the implementation behaved as a padding oracle, which made it possible to decrypt and re-encrypt query string parameters under certain conditions. Initially, the researchers abused the weakness using the Padre tool before later improving the process through the AMPScript MicrositeURL function.  This allowed them to forge valid QS values and access workflows such as “Forward to a Friend,” which could resolve subscriber identifiers into actual email addresses.  One of the most concerning aspects of the vulnerability was SFMC’s use of a single static encryption key shared across tenants. Researchers stated that once the cryptographic structure became understood, attackers could theoretically enumerate subscribers and access email content across multiple organizations using the same mechanism.

Legacy Encryption Weaknesses Expanded the Attack Surface 

The researchers also uncovered an older URL format that relied on per-parameter “encryption.” However, the mechanism reportedly consisted of a repeating static XOR key combined with a checksum. Although the scheme was considered legacy functionality, researchers found that it still worked on modern SFMC tenants. Because the implementation lacked strong cryptographic protections, attackers could decrypt and enumerate parameters such as JobID and ListSubscriber at high speed without relying on the slower padding-oracle technique.  The findings highlighted how legacy systems inside large cloud platforms can continue to create security exposure long after newer protections are introduced. 

Impact of the Salesforce Marketing Cloud Vulnerability 

Researchers concluded that the combined vulnerabilities could have enabled attackers to: 
  • Enumerate and exfiltrate subscriber records  
  • Access sent marketing emails and engagement data  
  • Forge cross-tenant QS tokens  
  • Access emails belonging to other organizations  
  • Exploit hard-coded cryptographic material  
  • Abuse argument-injection flaws tied to the MicrositeURL function  
  • Manipulate CloudPages and other SFMC web workflows  
To address the issues, Salesforce assigned multiple CVEs covering several root causes, including insecure cryptographic implementations, hard-coded keys, and argument injection vulnerabilities affecting MicrositeURL and CloudPages components.  According to Salesforce, the vulnerabilities were reported on 16 January 2026. Mitigations were deployed between 21 January and 24 January 2026. The company stated that it had identified no confirmed malicious exploitation at the time of disclosure.  As part of the remediation process, Salesforce migrated Marketing Cloud Engagement encryption to AES-GCM, rotated encryption keys, and disabled the double evaluation behavior tied to AMPScript subject-line rendering.  The company also invalidated all legacy tracking and CloudPages links created before 21 January 2026 at 23:00 UTC. Those links expired globally on 23 January 2026 at 21:00 UTC. 
  • ✇Firewall Daily – The Cyber Express
  • Operation TrustTrap Reveals 16,800 Fake Domains Exploiting User Trust Ashish Khaitan
    In a world where digital threats are becoming more confusing, Cyble Research and Intelligence Labs (CRIL) has uncovered one of the most extensive deceptive domain spoofing campaigns to date. Dubbed Operation TrustTrap, this large-scale operation has leveraged over 16,800 malicious domains to exploit cognitive trust mechanisms and harvest sensitive user data from unsuspecting victims. The scope and scale of this operation reveal a shift in how cybercriminals are evolving their tacti
     

Operation TrustTrap Reveals 16,800 Fake Domains Exploiting User Trust

Operation TrustTrap

In a world where digital threats are becoming more confusing, Cyble Research and Intelligence Labs (CRIL) has uncovered one of the most extensive deceptive domain spoofing campaigns to date.

Dubbed Operation TrustTrap, this large-scale operation has leveraged over 16,800 malicious domains to exploit cognitive trust mechanisms and harvest sensitive user data from unsuspecting victims.

The scope and scale of this operation reveal a shift in how cybercriminals are evolving their tactics to bypass traditional technical security measures.

What is Operation TrustTrap

Since early 2026, CRIL has been tracking a well-coordinated infrastructure involving a massive network of spoofed domains. These domains were designed to mimic legitimate government portals, particularly those related to transportation services like Department of Motor Vehicles (DMV) portals, toll payment systems, and vehicle registration services in the United States. The aim of this campaign is clear: credential and payment card harvesting through the exploitation of trusted government-facing services.

However, the technical complexity of the attack isn't based on advanced hacking techniques. Instead, Operation TrustTrap exploits how humans visually interpret URLs. By embedding government-like subdomains, attackers have created fraudulent domains that resemble legitimate government addresses, deceiving individuals into visiting these sites and providing sensitive information.

Tencent Cloud and Alibaba Cloud APAC

The spoofed domains were predominantly hosted on Tencent Cloud and Alibaba Cloud APAC, both of which have significant data centers in the Asia-Pacific region. These platforms have been linked to the infrastructure of the campaign, and their concentrated use adds another layer of complexity to the attribution process.

Furthermore, CRIL found that the domains were primarily registered through Gname.com Pte. Ltd., a registrar known for its significant Chinese customer base. Other registrars, such as Dominet (HK) Limited and NameSilo LLC, were also identified in the campaign.

These domain names were often associated with .bond, .cc, and .cfd top-level domains (TLDs), which were frequently used to evade detection and blacklisting.

The Key Technique: Subdomain Trust Injection

The most common method used in Operation TrustTrap is subdomain trust injection. This technique involves embedding trusted government tokens, such as mass.gov or wa.gov, in subdomains rather than the root domain. In legitimate URLs, the .gov component typically appears at the end of the domain string, but in these malicious domains, .gov is cleverly placed as part of a subdomain.

For instance, a URL such as mass.gov-bzyc[.]cc will lead a user to believe they are accessing an official Massachusetts government page, but in reality, they are on a fraudulent site designed to capture personal and financial data.

[caption id="" align="alignnone" width="1024"]Fake Massachusetts RMV citation landing page Fake Massachusetts RMV citation landing page (Source: Cyble)[/caption]

This manipulation of the domain’s structure is visually convincing, but it bypasses traditional security filters that only check the root domain for trusted indicators like .gov.

Another obfuscation technique used is hyphen-based semantic manipulation, where hyphens are inserted into familiar government identifiers to create visually similar URLs. This tactic further complicates the detection of malicious domains.

Global Targeting and Regional Focus

While Operation TrustTrap is heavily focused on the United States, targeting state portals such as those in California, Washington, and Florida, the operation is not confined to one region. CRIL identified similar spoofing efforts targeting government portals in India, Vietnam, and the United Kingdom.

In India, attackers have specifically targeted portals that follow the .gov.in domain structure. By injecting subdomains like www.in.gov-bond, the attackers were able to replicate the appearance of legitimate government websites, particularly those related to the Indian Department of National Investigation (NIA) and other defense-adjacent sites.

[caption id="" align="alignnone" width="939"]APT36 impersonating NIA, India operating at nia[.]gov[.]in[.]in3ymonaq[.]casa APT36 impersonating NIA (Source: Cyble)[/caption]

This specific targeting suggests that the threat actor has knowledge of government infrastructure and how it operates.

APT36 and the Connection to Operation TrustTrap

In addition to the use of Tencent Cloud and Alibaba Cloud, the tactics, techniques, and procedures (TTPs) observed in the campaign bear a striking resemblance to those used by APT36 (also known as Transparent Tribe). This Pakistan-based Advanced Persistent Threat (APT) group has a long history of targeting Indian government entities, defense personnel, and diplomatic infrastructure.

The infrastructure used in Operation TrustTrap shows similarities to APT36’s previous campaigns, particularly in terms of the domain registration patterns and use of Tencent Cloud and Alibaba Cloud APAC infrastructure. Furthermore, the behavior observed, including domain rotation and the use of disposable domains, matches previous APT36 activities.

Registrar and Hosting Analysis

The dominance of Gname.com as the registrar of choice for over 70% of the spoofed domains points to a specific trend in the campaign’s operational setup. This Singapore-based registrar, which serves a large number of Chinese entities, is part of the broader infrastructure strategy that focuses on low-cost hosting in the Asia-Pacific region.

Notably, Tencent Cloud and Alibaba Cloud APAC offer cloud services with global reach, providing the necessary infrastructure to scale this type of malicious operation. These services have been instrumental in supporting the rapid deployment of phishing sites across a variety of government services, especially those involving time-sensitive financial transactions.

❌
❌